Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-1597

31
FAUCET Score

CVE-2024-1597 is a critical SQL injection vulnerability in pgjdbc, the PostgreSQL JDBC Driver, affecting versions prior to 42.7.2 and others, specifically when using the non-default PreferQueryMode=SIMPLE. This flaw allows an unauthenticated attacker to inject SQL by crafting specific numeric and string placeholders, bypassing parameterized query protections. With a CVSS score of 9.8 (Critical), the vulnerability has a high impact on confidentiality, integrity, and availability, requiring no user interaction or privileges. While there is no known active exploitation or public exploit code, the vulnerability has garnered significant community discussion and media coverage, indicating high awareness.

Impacted Technologies

VendorProductVersion(s)CPE
< 42.2.28CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*
>= 42.3.0, < 42.3.9CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*
>= 42.4.0, < 42.4.4CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*
>= 42.5.0, < 42.5.5CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*
>= 42.6.0, < 42.6.1CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql_jdbc_driver:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

10.0CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.81%
Probability of exploitation in next 30 days
EPSS Percentile
91.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0481 is in the 85th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (43)

mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.6.1
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.7.2
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.2.28
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.3.9
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.4.4
mavenpatch availablevia ghsa
Product: org.postgresql:postgresqlFixed in: 42.5.5
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Advanced Update SupportFixed in: postgresql-jdbc-0:42.2.3-5.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Telecommunications Update ServiceFixed in: postgresql-jdbc-0:42.2.3-5.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Update Services for SAP SolutionsFixed in: postgresql-jdbc-0:42.2.3-5.el8_2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportFixed in: postgresql-jdbc-0:42.2.3-7.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Telecommunications Update ServiceFixed in: postgresql-jdbc-0:42.2.3-7.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.4 Update Services for SAP SolutionsFixed in: postgresql-jdbc-0:42.2.3-7.el8_4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportFixed in: postgresql-jdbc-0:42.2.3-5.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceFixed in: postgresql-jdbc-0:42.2.3-5.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsFixed in: postgresql-jdbc-0:42.2.3-5.el8_6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.8 Extended Update SupportFixed in: postgresql-jdbc-0:42.2.14-5.el8_8
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: postgresql-jdbc-0:42.2.28-1.el9_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Extended Update SupportFixed in: postgresql-jdbc-0:42.2.28-1.el9_0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Extended Update SupportFixed in: postgresql-jdbc-0:42.2.28-1.el9_2
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso76-openshift-rhel8:7.6-42
View patch
redhatpatch availablevia redhat_api
Product: RHEL-8 based Middleware ContainersFixed in: rh-sso-7/sso7-rhel8-operator-bundle:7.6.7-4
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-ephemeral-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-data-index-postgresql-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-ephemeral-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-jobs-service-postgresql-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-kn-workflow-cli-artifacts-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-operator-bundle:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-rhel8-operator:1.33.0-3
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-swf-builder-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHOSS-1.33-RHEL-8Fixed in: openshift-serverless-1/logic-swf-devmode-rhel8:1.33.0-5
View patch
redhatpatch availablevia redhat_api
Product: RHINT Camel-K 1.10.7Fixed in: pgjdbc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Apache Camel 4.4.1 for Spring Boot 3.2Fixed in: pgjdbc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Keycloak 24Fixed in: pgjdbc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 2.13.9.SP2Fixed in: org.postgresql/postgresql:42.5.6.redhat-00001
View patch
redhatpatch availablevia redhat_api
Product: Red Hat build of Quarkus 3.2.11.FinalFixed in: org.postgresql/postgresql:42.6.1.redhat-00001
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: postgresql-jdbc-0:42.2.14-3.el8_9
View patch
redhatno patchvia redhat_api
Product: Red Hat build of Apache Camel for Spring Boot 3Fixed in: pgjdbc
redhatend of lifevia redhat_api
Product: Red Hat build of OptaPlanner 8Fixed in: pgjdbc
redhatend of lifevia redhat_api
Product: Red Hat build of Apache Camel 4 for Quarkus 3Fixed in: pgjdbc
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: libreoffice:flatpak/postgresql-jdbc
redhatend of lifevia redhat_api
Product: Red Hat Integration Camel Quarkus 2Fixed in: pgjdbc
redhatend of lifevia redhat_api
Product: Red Hat Process Automation 7Fixed in: pgjdbc
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: libreoffice:flatpak/postgresql-jdbc

Vendor Advisories (2)

mavenGHSA-24rp-q3w6-vc56critical

org.postgresql:postgresql vulnerable to SQL Injection via line comment generation

Feb 21, 2024
redhatCVE-2024-1597Important

pgjdbc: PostgreSQL JDBC Driver allows attacker to inject SQL if using PreferQueryMode=SIMPLE

Feb 19, 2024

References

lists.debian.org / debian-lts-announce/2024/12/msg00017.html
sonarsource.com / blog/double-dash-double-trouble-a-subtle-sql-injection-flaw
github.com / pgjdbc/pgjdbc/security/advisories/GHSA-24rp-q3w6-vc56
Third Party Advisory
lists.debian.org / debian-lts-announce/2024/05/msg00007.html
lists.fedoraproject.org / archives/list/[email protected]/message/TZQTSMESZD2RJ5XBPSXH3TIQVUW5DIUU
Mailing ListThird Party Advisory
security.netapp.com / advisory/ntap-20240419-0008
enterprisedb.com / docs/jdbc_connector/latest/01_jdbc_rel_notes
Release Notes
enterprisedb.com / docs/security/assessments/cve-2024-1597
Third Party Advisory
openwall.com / lists/oss-security/2024/04/02/6