Database Access Control Flaw in Odoo Products
CVE-2018-14885

9.8CRITICAL

Key Information:

Vendor

Odoo

Status
Vendor
CVE Published:
28 June 2019

What is CVE-2018-14885?

The Odoo platform has a significant flaw in its database manager component affecting both Community and Enterprise versions 10.0 and 11.0. This vulnerability enables remote attackers to restore a database dump without requiring super-admin credentials, potentially exposing sensitive information. The issue arises from inadequate access controls, allowing an arbitrary password to succeed in the restoration process, thus bypassing the intended authentication mechanisms.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.