postgresql-jdbc: SQL injection due improper escaping of JDBC statement parameters
Published Oct 6, 2012
7.5
HIGHCVSS 2.0
EPSS 2.94%
Description
Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks. NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.
Affected products
No data.
- 9.1
- 8.1
No data.
Red Hat Enterprise Linux 5
postgresql-jdbc
Not affected
Red Hat Enterprise Linux 6
postgresql-jdbc
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | postgresql-jdbc | Not affected | n/a |
| Red Hat Enterprise Linux 6 | postgresql-jdbc | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
The upstream development team of the JDBC driver for the PostgreSQL database does not consider improper escaping of certain JDBC statement / query parameters, when the JDBC driver of version older than the version of underlying PostgresSQL server is being used, to be a security defect. In general, the JDBC driver for the PostgreSQL database does not promise to work with server releases newer than the driver release. The Red Hat Security Response Team agrees with their assessment and so does not consider this to be a security flaw.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
No CVSS v3.0 score for this CVE.
AV:N/AC:L/Au:N/C:P/I:P/A:P
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 2.94% (0.02942) | 86.65th | v5 (v2026.06.15) |
| Jun 15, 2026 | 2.94% (0.02942) | 85.29th | v5 (v2026.06.15) |
| Mar 17, 2025 | 1.92% (0.01915) | 82.10th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.62% (0.00623) | 79.60th | v3 (v2023.03.01) |
| Feb 8, 2024 | 0.62% (0.00623) | 78.25th | v3 (v2023.03.01) |
| Apr 24, 2023 | 0.62% (0.00623) | 75.77th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.60% (0.00596) | 75.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 2.17% (0.02172) | 80.77th | v2 (v2022.01.01) |
| Apr 1, 2022 | 2.17% (0.02172) | 78.91th | v2 (v2022.01.01) |
| Feb 4, 2022 | 2.17% (0.02172) | 57.73th | v2 (v2022.01.01) |
No CWE recorded.
References (17)
- http://archives.neohapsis.com/archives/bugtraq/2012-03/0126.html mailing-listx_refsource_BUGTRAQ
- http://lists.opensuse.org/opensuse-security/2012-03/msg00024.html mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/03/30/8 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/03/30/9 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/03/31/1 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/04/02/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/04/04/11 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/04/04/4 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/04/04/5 mailing-listx_refsource_MLIST
- http://www.openwall.com/lists/oss-security/2012/04/04/9 mailing-listx_refsource_MLIST
- http://www.osvdb.org/80641 vdb-entryx_refsource_OSVDB
- https://access.redhat.com/security/cve/CVE-2012-1618 Vendor Advisory
- https://bugzilla.novell.com/show_bug.cgi?id=754273 x_refsource_MISC
- https://bugzilla.redhat.com/show_bug.cgi?id=807394 Issue Tracking
- https://github.com/advisories/GHSA-h86w-m5rm-xr33 Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2012-1618
- https://www.cve.org/CVERecord?id=CVE-2012-1618
Change history (0)
No recorded changes yet.