CVE-2012-1618

Interaction error in the PostgreSQL JDBC driver before 8.2, when used with a PostgreSQL server with the "standard_conforming_strings" option enabled, such as the default configuration of PostgreSQL 9.1, does not properly escape unspecified JDBC statement parameters, which allows remote attackers to perform SQL injection attacks.  NOTE: as of 20120330, it was claimed that the upstream developer planned to dispute this issue, but an official dispute has not been posted as of 20121005.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 78%
VendorProductVersion
postgresqlpostgresql
9.1
postgresqlpostgresql_jdbc_driver
8.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libpgjava
bullseye (security)
42.2.15-1+deb11u1
fixed
bullseye
42.2.15-1+deb11u1
fixed
bookworm
42.5.4-1
fixed
sid
42.7.3-1
fixed
trixie
42.7.3-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libpgjava
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
not-affected
hardy
ignored