CVE-2018-25088: Blue Yonder postgraas_server PostgreSQL Backend postgres_cluster_driver.py create_postgres_db sql injection
A vulnerability, which was classified as critical, was found in Blue Yonder postgraasserver up to 2.0.0b2. Affected is the function createpgconnection/createpostgresdb of the file postgraasserver/backends/postgrescluster/postgresclusterdriver.py of the component PostgreSQL Backend Handler. The manipulation leads to sql injection. Upgrading to version 2.0.0 is able to address this issue. The patch is identified as 7cd8d016edc74a78af0d81c948bfafbcc93c937c. It is recommended to upgrade the affected component. VDB-234246 is the identifier assigned to this vulnerability.
Other sources
A vulnerability, which was classified as critical, was found in Blue Yonder postgraasserver up to 2.0.0b2. Affected is the function createpgconnection/createpostgresdb of the file postgraasserver/backends/postgrescluster/postgresclusterdriver.py of the component PostgreSQL Backend Handler. The manipulation leads to sql injection. Upgrading to version 2.0.0 is able to address this issue. The patch is identified as 7cd8d016edc74a78af0d81c948bfafbcc93c937c. It is recommended to upgrade the affected component. VDB-234246 is the identifier assigned to this vulnerability.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-25088?
CVE-2018-25088 is classified as a critical vulnerability.
How do I fix CVE-2018-25088?
To fix CVE-2018-25088, upgrade the postgraas_server to version 2.0.0 or later.
What components are affected by CVE-2018-25088?
CVE-2018-25088 affects the _create_pg_connection/create_postgres_db function in the postgraas_server component.
Which software versions are impacted by CVE-2018-25088?
CVE-2018-25088 impacts postgraas_server versions up to 2.0.0-beta2.
Who is responsible for the postgraas_server affected by CVE-2018-25088?
The postgraas_server affected by CVE-2018-25088 is developed by Blue Yonder.