Current Description

If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

View Analysis Description

Analysis Description

If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

Severity

CVSS 3.x Severity and Metrics:

CVSS 2.0 Severity and Metrics:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to [email protected].

Weakness Enumeration

CWE-ID CWE Name Source
NVD-CWE-noinfo Insufficient Information NIST  

Change History

1 change records found show changes

Initial Analysis 10/05/2022 11:49:13 AM

Action Type Old Value New Value
Added CPE Configuration
OR
     *cpe:2.3:a:actian:psql:*:*:*:*:*:*:*:* versions from (including) 11 up to (including) 13
     *cpe:2.3:a:actian:zen:*:*:*:*:*:*:*:* versions from (including) 14.0 up to (excluding) 14.21.022
     *cpe:2.3:a:actian:zen:*:*:*:*:*:*:*:* versions from (including) 15.0 up to (excluding) 15.01.017
Added CVSS V3.1
NIST AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Added CWE
NIST NVD-CWE-noinfo
Changed Reference Type
https://actian.my.salesforce.com/sfc/p/#300000001XnW/a/4y000000LhjZ/s7Hk0dFM1Z9nLuAPa50rMaZie7mqCR5u33NZFbdKT7Q No Types Assigned
https://actian.my.salesforce.com/sfc/p/#300000001XnW/a/4y000000LhjZ/s7Hk0dFM1Z9nLuAPa50rMaZie7mqCR5u33NZFbdKT7Q Vendor Advisory
Changed Reference Type
https://www.actian.com/support-services/ No Types Assigned
https://www.actian.com/support-services/ Vendor Advisory