CVE-2018-14885: Critical severity odoo vulnerability
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the super-admin password. An arbitrary password succeeds.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2018-14885.
What is the severity of CVE-2018-14885?
The severity of CVE-2018-14885 is critical.
What is the affected software for CVE-2018-14885?
The affected software for CVE-2018-14885 includes Odoo Community 10.0 and 11.0, and Odoo Enterprise 10.0 and 11.0.
How does CVE-2018-14885 allow a remote attacker to restore a database dump?
CVE-2018-14885 allows a remote attacker to restore a database dump without knowing the super-admin password.
Are there any references available for CVE-2018-14885?
Yes, you can find more information about CVE-2018-14885 in the following references: [GitHub Commits](https://github.com/odoo/odoo/commits/master) and [GitHub Issue](https://github.com/odoo/odoo/issues/32512).