CVE-2023-41119
HIGHEnterpriseDB Postgres Advanced Server <15.4.0 - Privilege Escalation
Title source: llmDescription
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It contains the function _dbms_aq_move_to_exception_queue that may be used to elevate a user's privileges to superuser. This function accepts the OID of a table, and then accesses that table as the superuser by using SELECT and DML commands.
References (1)
Core 1
Core References
Scores
CVSS v3
8.8
EPSS
0.0063
EPSS Percentile
45.2%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (1)
enterprisedb/postgres_advanced_server
< 11.21.32
Published
Dec 12, 2023
Tracked Since
Feb 18, 2026