Actian develops data management and analytics products including relational databases and embedded systems such as Ingres, Zen, Matrix, and Pervasive PSQL that serve specialized enterprise and embedded deployments. Observed vulnerabilities concentrate on input-handling and access-control weaknesses including SQL injection, permission assignment flaws, and integer underflow conditions typical of database and storage software; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Actian over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40756HIGH If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 | Sep 30, 2022 | 8.8 | 27 | NO | NO |
CVE-2017-11757CRITICAL Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583. The overflow occurs a | Jul 31, 2017 | 9.8 | 25 | NO | NO |
CVE-2008-3357HIGH Untrusted search path vulnerability in ingvalidpw in Ingres 2.6, Ingres 2006 release 1 (aka 9.0.4), and Ingres 2006 release 2 (aka 9.1.0) on Linux and HP-UX allows local users to g | Aug 5, 2008 | 7.2 | 20 | NO | NO |
CVE-2015-3993MEDIUM Actian Matrix 5.1.x through 5.1.2.4 and 5.2.x through 5.2.0.1 allows remote authenticated users to bypass intended write-access restrictions and execute an UPDATE statement by refe | Jun 13, 2015 | 6.5 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Actian.
Media articles that mention a CVE ID that affects a product developed by Actian — matched by CVE ID, not by vendor name.