First published: Fri May 11 2018(Updated: )
Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Greenplum Command Center | >=2.0.0<2.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1280 is classified as a high severity vulnerability due to its ability to allow unauthenticated users to perform SQL injections.
To fix CVE-2018-1280, upgrade Pivotal Greenplum Command Center to version 2.5.1 or later.
CVE-2018-1280 affects all versions of Pivotal Greenplum Command Center from 2.0.0 to 2.5.0.
CVE-2018-1280 is a blind SQL injection vulnerability that allows exposure of database contents.
Yes, untrusted users can exploit CVE-2018-1280 to gain unauthorized access to sensitive database information.