Vertica
Vendor:
First CVE: Nov 4, 2015 · Active for 10 years
8
Total CVEs
More Total CVEs than 85% of tracked products
1.6
Avg CVEs / Year
Higher CVE frequency than 59% of tracked products
8.3
Avg CVSS
Higher Avg CVSS than 73% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Vertica over time
Volume of CVEsAvg CVSS Base Score
First CVE
Nov 4, 2015
10 years ago
Most Recent CVE
Mar 13, 2026
136 days ago
CVE Severity & Scoring
Vertica8 CVEs
25%
25%
50%
All CVEs352,785 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network7 (87.5%)
Unknown1 (12.5%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low7 (87.5%)
High0 (0.0%)
Unknown1 (12.5%)
User Interaction
None5 (62.5%)
Unknown1 (12.5%)
Required2 (25.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None7 (87.5%)
Unknown1 (12.5%)
Top CVEs
Signals from CVEs in this product scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-2002CRITICAL The validateAdminConfig handler in the Analytics Management Console in HPE Vertica 7.0.x before 7.0.2.12, 7.1.x before 7.1.2-12, and 7.2.x before 7.2.2-1 allows remote attackers to | Apr 20, 2016 | 9.8 | 31 | NO | NO |
CVE-2025-12455HIGH Observable response discrepancy vulnerability in OpenText™ Vertica allows Password Brute Forcing.
The vulnerability could lead to Password Brute Forcing in Vertica management con | Mar 13, 2026 | 7.5 | 30 | NO | NO |
CVE-2017-5802CRITICAL A Remote Gain Privileged Access vulnerability in HPE Vertica Analytics Platform version v4.1 and later was found. | Feb 15, 2018 | 9.8 | 30 | NO | NO |
CVE-2015-6867HIGH The vertica-udx-zygote process in HP Vertica 7.1.1 UDx does not require authentication, which allows remote attackers to execute arbitrary commands via a crafted packet, aka ZDI-CA | Nov 4, 2015 | 7.5 | 27 | NO | NO |
CVE-2024-6360CRITICAL Incorrect Permission Assignment for Critical Resource vulnerability in OpenText™ Vertica could allow Privilege Abuse and result in unauthorized access or privileges to Vertica agen | Oct 2, 2024 | 9.8 | 26 | NO | NO |
CVE-2023-7248CRITICAL
Certain functionality in OpenText Vertica Management console might be prone to bypass via crafted requests.
The vulnerability would affect one of Vertica’s authentication functi | Mar 15, 2024 | 9.8 | 25 | NO | NO |
CVE-2025-12454MEDIUM Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.
The vulnerability could lead to Refle | Mar 13, 2026 | 6.1 | 21 | NO | NO |
CVE-2025-12453MEDIUM Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText™ Vertica allows Reflected XSS.
The vulnerability could lead to Refle | Mar 13, 2026 | 6.1 | 21 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (8 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (8 CVEs).
Media Mentions
Signals from CVEs in this product scope (8 CVEs).
Top CNAs Publishing CVEs For Vertica
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 7.1.1 | 1 | 7.5 | 4.7% | 0 | 0 |
| 24.3.0-0 | 1 | 9.8 | 0.3% | 0 | 0 |