CVE-2023-5869 PUBLISHED CVSS 8.800000190734863 HIGH

An attacker running as an authenticated PostgreSQL user can provide crafted data and trigger the integer overflow due to such missing overflow check. This can enable the execution of arbitrary code in the system.

EPSS 1.65% · 81.9th percentile

Risk Scores

CVSS v3.1
8.800000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:F/RL:U/RC:C
EPSS Score
1.65%
81.9th percentile

Affected Products

VendorProductVersions
ABBABB Ability™ Symphony® Plus S+ Engineering 2.2
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3 RU1
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3 RU3
ABBABB Ability™ Symphony® Plus S+ Engineering 2.4 SP2
ABBABB Ability™ Symphony® Plus S+ Engineering 2.4
ABBABB Ability™ Symphony® Plus S+ Engineering 2.3 RU2
ABBABB Ability™ Symphony® Plus S+ Engineering 2.4 SP1

Timeline

References

Open in Interactive Console →