CVE-2016-6656 - CVE House
Back to Database
Status published High CVE-2016-6656

An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation...

Vulnerability Description

An issue was discovered in Pivotal Greenplum before 4.3.10.0. Creation of external tables using GPHDFS protocol has a vulnerability whereby arbitrary commands can be injected into the system. In order to exploit this vulnerability the user must have superuser 'gpadmin' access to the system or have been granted GPHDFS protocol permissions in order to create a GPHDFS external table.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2016-6656

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Pivotal Greenplum 4.3.0.0 to 4.3.9.1 and older versions that are end of life
Vulnerable Versions:
Pivotal Greenplum 4.3.0.0 to 4.3.9.1 and older versions that are end of life

Timeline

Official Publish: December 16th, 2016
Last Modified: August 6th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.