Actian Zen PSQL Vulnerability: Unauthorized Access to Database via Security File Removal

Actian Zen PSQL Vulnerability: Unauthorized Access to Database via Security File Removal

CVE-2022-40756 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

Learn more about our Cis Benchmark Audit For Microsoft Sql Server.