Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2009-3230

21
FAUCET Score

CVE-2009-3230 is a privilege escalation vulnerability affecting multiple versions of PostgreSQL (8.4.1 and earlier, 8.3.8 and earlier, 8.2.14 and earlier, 8.1.18 and earlier, 8.0.22 and earlier, and 7.4.26 and earlier). Remote authenticated users can gain privileges by exploiting improper privilege handling during RESET ROLE and RESET SESSION AUTHORIZATION operations, an incomplete fix for a previous CVE. With a CVSS score of 6.5, this vulnerability is of medium severity, allowing for partial confidentiality, integrity, and availability impact with low attack complexity. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on CISA's KEV catalog. Community discussion is minimal, with only one mention found.

Impacted Technologies

VendorProductVersion(s)CPE
7.4CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4:*:*:*:*:*:*:*
7.4.1CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.1:*:*:*:*:*:*:*
7.4.2CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.2:*:*:*:*:*:*:*
7.4.3CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.3:*:*:*:*:*:*:*
7.4.4CPE matchmatch criteria
cpe:2.3:a:postgresql:postgresql:7.4.4:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.5MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:P

Confidentiality Impact
PARTIAL
Integrity Impact
PARTIAL
Availability Impact
PARTIAL
Access Vector
NETWORK
Access Complexity
LOW
Authentication
SINGLE
Exploitability Score
8.0
Impact Score
6.4
CvssVersion
2.0

Exploit Intelligence

EPSS Score
2.83%
Probability of exploitation in next 30 days
EPSS Percentile
85.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0283 is in the 95th percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 3Fixed in: rh-postgresql-0:7.3.21-2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4Fixed in: postgresql-0:7.4.26-1.el4_8.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: postgresql-0:8.1.18-2.el5_4.1
View patch

Vendor Advisories (1)

redhatCVE-2009-3230Moderate

postgresql: SQL privilege escalation, incomplete fix for CVE-2007-6600

Sep 9, 2009

References

archives.postgresql.org / pgsql-www/2009-09/msg00024.php
lists.opensuse.org / opensuse-security-announce/2009-10/msg00001.html
lists.opensuse.org / opensuse-security-announce/2009-10/msg00004.html
marc.info
bugzilla.redhat.com / show_bug.cgi
secunia.com / advisories/36660
Vendor Advisory
secunia.com / advisories/36695
Vendor Advisory
secunia.com / advisories/36727
Vendor Advisory
secunia.com / advisories/36800
secunia.com / advisories/36837
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A10166
sunsolve.sun.com / search/document.do
redhat.com / archives/fedora-package-announce/2009-September/msg00305.html
redhat.com / archives/fedora-package-announce/2009-September/msg00307.html
wiki.rpath.com / wiki/Advisories:rPSA-2010-0012
postgresql.org / docs/8.3/static/release-8-3-8.html
Vendor Advisory
postgresql.org / support/security.html
Vendor Advisory
securityfocus.com / archive/1/509917/100/0/threaded
securityfocus.com / bid/36314
ubuntu.com / usn/usn-834-1
us.debian.org / security/2009/dsa-1900
vupen.com / english/advisories/2009/2602
Vendor Advisory