SB2020072503 - Improper authorization in F5 BIG-IQ Centralized Management PostgreSQL component



SB2020072503 - Improper authorization in F5 BIG-IQ Centralized Management PostgreSQL component

Published: July 25, 2020 Updated: November 28, 2024

Security Bulletin ID SB2020072503
Severity
Low
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Data manipulation

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Improper Authorization (CVE-ID: CVE-2020-1720)

The vulnerability allows a remote attacker to perform unauthorized modification of data in database.

The vulnerability exists due to the ALTER ... DEPENDS ON EXTENSION sub-commands do not perform authorization checks, which can allow an unprivileged user to drop any function, procedure, materialized view, index, or trigger under certain conditions. This attack is possible if an administrator has installed an extension and an unprivileged user can CREATE, or an extension owner either executes DROP EXTENSION predictably or can be convinced to execute DROP EXTENSION.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.