Postgres Advanced Server
Vendor:
First CVE: Aug 31, 2007 · Active for 18 years
10
Total CVEs
More Total CVEs than 88% of tracked products
5.0
Avg CVEs / Year
Higher CVE frequency than 87% of tracked products
7.0
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Postgres Advanced Server over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 31, 2007
18 years ago
Most Recent CVE
Dec 12, 2023
955 days ago
CVE Severity & Scoring
Postgres Advanced Server10 CVEs
60%
30%
10%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network9 (90.0%)
Unknown1 (10.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low9 (90.0%)
High0 (0.0%)
Unknown1 (10.0%)
User Interaction
None9 (90.0%)
Unknown1 (10.0%)
Required0 (0.0%)
Privileges Required
Low7 (70.0%)
High0 (0.0%)
None2 (20.0%)
Unknown1 (10.0%)
Top CVEs
Signals from CVEs in this product scope (10 CVEs).
10 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4639MEDIUM EnterpriseDB Advanced Server 8.2 does not properly handle certain debugging function calls that occur before a call to pldbg_create_listener, which allows remote authenticated user | Aug 31, 2007 | 6.5 | 27 | NO | YES |
CVE-2023-41117CRITICAL An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 9.8 | 25 | NO | NO |
CVE-2023-31043HIGH EnterpriseDB EDB Postgres Advanced Server (EPAS) before 14.6.0 logs unredacted passwords in situations where optional parameters are used with CREATE/ALTER USER/GROUP/ROLE, and red | Apr 23, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-41119HIGH An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-41118HIGH An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 8.8 | 22 | NO | NO |
CVE-2023-41115MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. Whe | Dec 12, 2023 | 6.5 | 19 | NO | NO |
CVE-2023-41120MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 6.5 | 17 | NO | NO |
CVE-2023-41114MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 6.5 | 17 | NO | NO |
CVE-2023-41116MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 4.3 | 14 | NO | NO |
CVE-2023-41113MEDIUM An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. It | Dec 12, 2023 | 4.3 | 14 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (10 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
10.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (10 CVEs).
Media Mentions
Signals from CVEs in this product scope (10 CVEs).
Top CNAs Publishing CVEs For Postgres Advanced Server
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 8.2 | 1 | 6.5 | 5.1% | 0 | 1 |