Back

HIGH

postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters

Published Oct 6, 2012

Description

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.

Affected products

Remediation

Red Hat statement

The upstream development team of the JDBC driver for the PostgreSQL database does not consider improper escaping of certain JDBC statement / query parameters, when the JDBC driver of version older than the version of underlying PostgresSQL server is being used, to be a security defect. In general, the JDBC driver for the PostgreSQL database does not promise to work with server releases newer than the driver release. The Red Hat Security Response Team agrees with their assessment and so does not consider this to be a security flaw.

Metrics

Weaknesses (0)

No CWE recorded.

References (17)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Oct 6, 2012
Updated Aug 6, 2024
Reserved Mar 12, 2012
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Mar 25, 2012
GHSA-H86W-M5RM-XR33