Invalid json_populate_recordset or jsonb_populate_recordset function calls in PostgreSQL 10.x before 10.1, 9.6.x before 9.6.6, 9.5.x before 9.5.10, 9.4.x before 9.4.15, and 9.3.x before 9.3.20 can crash the server or disclose a few bytes of server memory.
結論預警: CVE-2017-15098 綜合評估為高風險(66.2/100):CVSS 技術影響為高級,利用機率(EPSS 3.72%) 核心證據: 近一日 EPSS 上升 +2.86%,被利用關注度持續升高。 強制指令: 被利用機率偏高—請盤點暴露面並優先安排修補。
風險隨態勢動態變化;本站持續評估並同步更新本頁展示內容。
EPSS 日更估計相對被利用可能性;百分位表示該 CVE 在已評分漏洞中的相對排名(越高表示相對更嚴重)。
| # | 日期 | 舊 EPSS 分數 | 新 EPSS 分數 | 變化(新 − 舊) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.86% | 3.72% | +2.86% |
| 2 | 2026-03-11 | 0.77% | 0.86% | +0.09% |
| 3 | 2025-12-08 | — | 0.77% | — |
完整 EPSS 歷史 (共 24 筆)
該 CVE 的 CVSS 指標。
| 底座分 | 版本 | 嚴重度 | 向量 | 可利用性 | 影響 | 分數來源 |
|---|---|---|---|---|---|---|
| 8.1 | 3.0 | HIGH |
|
2.8 | 5.2 | [email protected] |
| 5.5 | 2.0 | MEDIUM |
|
8.0 | 4.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
— | CVE-2017-15098: 3 source package rows (postgresql, postgresql14, postgresql15); 16 state rows across 11 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-community, 3.19-main, 3.20-community, 3.20-main, edge-community, edge-main); fixed 16, open 0. | https://security.alpinelinux.org/vuln/CVE-2017-15098 |
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2017-15098 |
suse
|
high | CVE-2017-15098 severity important: SUSE including 160 source package names (libecpg6, libecpg6-10.10-1.15.1, …), 1047 product×package rows across 75 product lines (HPE Helion OpenStack 8, SUSE CaaS Platform 4.0, … (75 product lines)): Known Not Affected 866, Fixed 181. | https://www.suse.com/security/cve/CVE-2017-15098/ |
ubuntu
|
medium | CVE-2017-15098 medium priority: Ubuntu including 5 source packages (postgresql-10, postgresql-9.1, postgresql-9.3, postgresql-9.5, postgresql-9.6), 40 status rows across 8 suites (artful, bionic, cosmic, disco, trusty, upstream, xenial, zesty): DNE 29, released 5, needs-triage 4, not-affected 2. | https://ubuntu.com/security/CVE-2017-15098 |
| 廠商 | 產品 | 版本 | 原始 CPE |
|---|---|---|---|
| postgresql | postgresql | 9.3 | cpe:2.3:a:postgresql:postgresql:9.3:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.1 | cpe:2.3:a:postgresql:postgresql:9.3.1:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.2 | cpe:2.3:a:postgresql:postgresql:9.3.2:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.3 | cpe:2.3:a:postgresql:postgresql:9.3.3:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.4 | cpe:2.3:a:postgresql:postgresql:9.3.4:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.5 | cpe:2.3:a:postgresql:postgresql:9.3.5:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.6 | cpe:2.3:a:postgresql:postgresql:9.3.6:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.7 | cpe:2.3:a:postgresql:postgresql:9.3.7:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.8 | cpe:2.3:a:postgresql:postgresql:9.3.8:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.9 | cpe:2.3:a:postgresql:postgresql:9.3.9:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.10 | cpe:2.3:a:postgresql:postgresql:9.3.10:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.11 | cpe:2.3:a:postgresql:postgresql:9.3.11:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.12 | cpe:2.3:a:postgresql:postgresql:9.3.12:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.13 | cpe:2.3:a:postgresql:postgresql:9.3.13:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.14 | cpe:2.3:a:postgresql:postgresql:9.3.14:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.15 | cpe:2.3:a:postgresql:postgresql:9.3.15:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.16 | cpe:2.3:a:postgresql:postgresql:9.3.16:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.17 | cpe:2.3:a:postgresql:postgresql:9.3.17:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.18 | cpe:2.3:a:postgresql:postgresql:9.3.18:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.3.19 | cpe:2.3:a:postgresql:postgresql:9.3.19:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4 | cpe:2.3:a:postgresql:postgresql:9.4:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.1 | cpe:2.3:a:postgresql:postgresql:9.4.1:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.2 | cpe:2.3:a:postgresql:postgresql:9.4.2:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.3 | cpe:2.3:a:postgresql:postgresql:9.4.3:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.4 | cpe:2.3:a:postgresql:postgresql:9.4.4:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.5 | cpe:2.3:a:postgresql:postgresql:9.4.5:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.6 | cpe:2.3:a:postgresql:postgresql:9.4.6:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.7 | cpe:2.3:a:postgresql:postgresql:9.4.7:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.8 | cpe:2.3:a:postgresql:postgresql:9.4.8:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.9 | cpe:2.3:a:postgresql:postgresql:9.4.9:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.10 | cpe:2.3:a:postgresql:postgresql:9.4.10:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.11 | cpe:2.3:a:postgresql:postgresql:9.4.11:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.12 | cpe:2.3:a:postgresql:postgresql:9.4.12:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.13 | cpe:2.3:a:postgresql:postgresql:9.4.13:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.4.14 | cpe:2.3:a:postgresql:postgresql:9.4.14:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5 | cpe:2.3:a:postgresql:postgresql:9.5:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.1 | cpe:2.3:a:postgresql:postgresql:9.5.1:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.2 | cpe:2.3:a:postgresql:postgresql:9.5.2:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.3 | cpe:2.3:a:postgresql:postgresql:9.5.3:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.4 | cpe:2.3:a:postgresql:postgresql:9.5.4:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.5 | cpe:2.3:a:postgresql:postgresql:9.5.5:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.6 | cpe:2.3:a:postgresql:postgresql:9.5.6:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.7 | cpe:2.3:a:postgresql:postgresql:9.5.7:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.8 | cpe:2.3:a:postgresql:postgresql:9.5.8:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.5.9 | cpe:2.3:a:postgresql:postgresql:9.5.9:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.6 | cpe:2.3:a:postgresql:postgresql:9.6:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.6.1 | cpe:2.3:a:postgresql:postgresql:9.6.1:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.6.2 | cpe:2.3:a:postgresql:postgresql:9.6.2:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.6.3 | cpe:2.3:a:postgresql:postgresql:9.6.3:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.6.4 | cpe:2.3:a:postgresql:postgresql:9.6.4:*:*:*:*:*:*:* |
| postgresql | postgresql | 9.6.5 | cpe:2.3:a:postgresql:postgresql:9.6.5:*:*:*:*:*:*:* |
| postgresql | postgresql | 10 | cpe:2.3:a:postgresql:postgresql:10:*:*:*:*:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| URL | 標籤 |
|---|---|
| http://www.securityfocus.com/bid/101781 | Third Party Advisory VDB Entry |
| http://www.securitytracker.com/id/1039752 | Third Party Advisory VDB Entry |
| https://access.redhat.com/errata/RHSA-2018:2511 | |
| https://access.redhat.com/errata/RHSA-2018:2566 | |
| https://www.debian.org/security/2017/dsa-4027 | Issue Tracking Third Party Advisory |
| https://www.debian.org/security/2017/dsa-4028 | Issue Tracking Third Party Advisory |
| https://www.postgresql.org/about/news/1801/ | Issue Tracking Vendor Advisory |
| https://www.postgresql.org/support/security/ | Issue Tracking Vendor Advisory |