CVE-2018-1280: SQL Injection
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1280?
CVE-2018-1280 is classified as a high severity vulnerability due to its ability to allow unauthenticated users to perform SQL injections.
How do I fix CVE-2018-1280?
To fix CVE-2018-1280, upgrade Pivotal Greenplum Command Center to version 2.5.1 or later.
Who is affected by CVE-2018-1280?
CVE-2018-1280 affects all versions of Pivotal Greenplum Command Center from 2.0.0 to 2.5.0.
What type of vulnerability is CVE-2018-1280?
CVE-2018-1280 is a blind SQL injection vulnerability that allows exposure of database contents.
Can untrusted users exploit CVE-2018-1280?
Yes, untrusted users can exploit CVE-2018-1280 to gain unauthorized access to sensitive database information.