Medium severity6.5NVD Advisory· Published Dec 12, 2023· Updated Jun 17, 2026
CVE-2023-41115
CVE-2023-41115
Description
An issue was discovered in EnterpriseDB Postgres Advanced Server (EPAS) before 11.21.32, 12.x before 12.16.20, 13.x before 13.12.16, 14.x before 14.9.0, and 15.x before 15.4.0. When using UTL_ENCODE, an authenticated user can read any large object, regardless of that user's permissions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:enterprisedb:postgres_advanced_server:*:*:*:*:*:*:*:*range: <11.21.32
- (no CPE)
- (no CPE)range: <11.21.32, <12.16.20, <13.12.16, <14.9.0, <15.4.0
Patches
Vulnerability mechanics
References
1- www.enterprisedb.com/docs/security/advisories/cve202341115/nvdVendor Advisory
News mentions
0No linked articles in our index yet.