CVE-2021-23214: SQL Injection
PostgreSQL is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements when the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, which could allow the attacker to view, add, modify or delete information in the back-end database.
Other sources
When the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, a man-in-the-middle attacker can inject arbitrary SQL queries when a connection is first established, despite the use of SSL certificate verification and encryption.
— MITRE
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-23214?
CVE-2021-23214 is a vulnerability in PostgreSQL that allows for SQL injection attacks.
How does the vulnerability in PostgreSQL work?
The vulnerability in PostgreSQL allows a remote attacker to send specially-crafted SQL statements when the server is configured to use trust authentication with a clientcert requirement or to use cert authentication, which could allow the attacker to view, add, modify, or delete information.
Which software versions are affected by the PostgreSQL vulnerability?
The PostgreSQL vulnerability affects IBM QRadar SIEM versions 7.5.0 GA, 7.4.3 GA - 7.4.3 FP4, and 7.3.3 GA - 7.3.3 FP10.
How severe is CVE-2021-23214?
CVE-2021-23214 has a severity rating of 8.1 (high).
How can I patch the PostgreSQL vulnerability in IBM QRadar SIEM?
To fix the PostgreSQL vulnerability in IBM QRadar SIEM, you can download the patches provided by IBM: 7.5.0-QRADAR-QRSIEM-20220215133427, 7.4.3-QRADAR-QRSIEM-20220307203834, and 7.3.3-QRADAR-QRSIEM-20220318161607.