Teradata maintains a focused portfolio of data warehouse, analytics, and gateway products, with observed vulnerabilities concentrating around input validation, link-following conditions, and use of hard-coded credentials in components such as its Virtual Machine, Studio Express, and Viewpoint administrative interface. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Teradata over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2016-7489CRITICAL Teradata Virtual Machine Community Edition v15.10's perl script /opt/teradata/gsctools/bin/t2a.pl creates files in /tmp in an insecure manner, this may lead to elevated code execut | Nov 10, 2016 | 9.8 | 31 | NO | NO |
CVE-2019-6499HIGH Teradata Viewpoint before 14.0 and 16.20.00.02-b80 contains a hardcoded password of TDv1i2e3w4 for the viewpoint database account (in viewpoint-portal\conf\server.xml) that could p | Jan 21, 2019 | 8.1 | 21 | NO | NO |
CVE-2015-5401HIGH Teradata Gateway before 15.00.03.02-1 and 15.10.x before 15.10.00.01-1 and TD Express before 15.00.02.08_Sles10 and 15.00.02.08_Sles11 allow remote attackers to cause a denial of s | May 23, 2017 | 7.5 | 20 | NO | NO |
CVE-2016-7490HIGH The installation script studioexpressinstall for Teradata Studio Express 15.12.00.00 creates files in /tmp insecurely. A malicious local user could create a symlink in /tmp and pos | Nov 10, 2016 | 7.8 | 20 | NO | NO |
CVE-2016-7488HIGH Teradata Virtual Machine Community Edition v15.10 has insecure file permissions on /etc/luminex/pkgmgr. These could allow a local user to modify its contents and execute commands a | Nov 10, 2016 | 7.8 | 20 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Teradata.
Media articles that mention a CVE ID that affects a product developed by Teradata — matched by CVE ID, not by vendor name.