CVE Vulnerabilities

CVE-2022-40756

Published: Sep 30, 2022 | Modified: Oct 05, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

Affected Software

Name Vendor Start Version End Version
Psql Actian 11 (including) 13 (including)
Zen Actian 14.0 (including) 14.21.022 (excluding)
Zen Actian 15.0 (including) 15.01.017 (excluding)

References