First published: Tue May 23 2017(Updated: )
Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of service (database crash) via a malformed CONFIG REQUEST message.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Teradata Database | =15.00.00 | |
Teradata Database | =15.10.00 | |
Teradata Teradata Gateway | <=15.00.02.08 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-5401 is considered a high severity vulnerability due to its potential to cause denial of service.
To mitigate CVE-2015-5401, upgrade Teradata Gateway to versions 15.00.03.02-1 or 15.10.00.01-1 or later.
CVE-2015-5401 affects Teradata Gateway versions prior to 15.00.03.02-1, 15.10.x versions before 15.10.00.01-1, and Teradata Express versions before 15.00.02.08.
CVE-2015-5401 allows remote attackers to exploit the vulnerability through a malformed CONFIG REQUEST message.
The impact of CVE-2015-5401 includes causing a denial of service, which can result in a database crash.