CVE Feed

    Dashboard / CVE / CVE-2022-40756

    CVE-2022-40756

    If folder security is misconfigured for Actian Zen PSQL BEFORE Patch Update 1 for Zen 15 SP1 (v15.11.005), Patch Update 4 for Zen 15 (v15.01.017), or Patch Update 5 for Zen 14 SP2 (v14.21.022), it can allow an attacker (with file read/write access) to remove specific security files in order to reset the master password and gain access to the database.

    Published:Sep 30, 2022
    Last Modified:May 20, 2025
    EPS:Sep 30, 2022
    EPSS Score:0.0023
    CVSS Score:8.8

    Affected Products

    Vendor
    Actian
    Product
    Psql
    Vendor
    Actian
    Product
    Zen

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High