Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2022-31197

26
FAUCET Score

CVE-2022-31197 is a SQL injection vulnerability in the PostgreSQL JDBC Driver (PgJDBC) affecting versions prior to 42.2.26 and 42.4.1. It arises from improper escaping of column names in the ResultSet.refreshRow() method, allowing an attacker to inject SQL commands. This vulnerability carries a high severity CVSS score of 8.0, indicating that a low-privileged attacker can achieve high impact on confidentiality, integrity, and availability with user interaction, by crafting malicious column names in a database under their control and tricking a privileged JDBC application into querying it and invoking refreshRow(). There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 42.2.26CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*
>= 42.3.0, < 42.3.7CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*
42.4.0CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.0:-:*:*:*:*:*:*
42.4.0CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.0:rc1:*:*:*:*:*:*
42.4.1CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:42.4.1:rc1:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.1HIGH

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
LOW
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.2
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.67%
Probability of exploitation in next 30 days
EPSS Percentile
74.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0167 is in the 89th percentile among its peer group of 890 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (11)

github_advisorypatch availablevia nvd_reference
View patch
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.4.1
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.2.26
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.3.7
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 2.7.7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 2.13.5Fixed in: postgresql
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql-jdbc-0:42.2.18-6.el9_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Fuse 7.11.1Fixed in: jdbc-postgresql
View patch
redhatno patchvia redhat_api
Product: Red Hat build of Apicurio Registry 2Fixed in: quarkus-jdbc-postgresql-deployment
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libreoffice:flatpak/libreoffice
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql-jdbc

Vendor Advisories (2)

mavenGHSA-r38f-c4h4-hqq2high

PostgreSQL JDBC Driver SQL Injection in ResultSet.refreshRow() with malicious column names

Aug 6, 2022
redhatCVE-2022-31197Moderate

postgresql: SQL Injection in ResultSet.refreshRow() with malicious column names

Aug 3, 2022

References

lists.debian.org / debian-lts-announce/2024/12/msg00017.html
github.com / pgjdbc/pgjdbc/commit/739e599d52ad80f8dcd6efedc6157859b1a9d637
PatchThird Party Advisory
github.com / pgjdbc/pgjdbc/security/advisories/GHSA-r38f-c4h4-hqq2
ExploitThird Party Advisory
lists.debian.org / debian-lts-announce/2022/10/msg00009.html
Mailing ListThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/I6WHUADTZBBQLVHO4YG4XCWDGWBT4LRP
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/UTFE6SV33P5YYU2GNTQZQKQRVR3GYE4S