Trustwave Database Security Knowledgebase version 6.04 includes new checks for Microsoft SQL Server, Oracle, MySQL, MongoDB, PostgreSQL, and Couchbase. It also introduces new policies for CIS.
Couchbase
– Cluster Management and Views endpoints are vulnerable to the Slowloris DoS attack
Risk: High
Microsoft SQL Server
– Microsoft SQL Server Elevation of Privilege Vulnerability - CVE-2021-1636
Risk: High
MongoDB
– Vulnerability in MongoDB Server - CVE-2018-20802
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2018-20803
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2018-20804
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2018-20805
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2019-20923
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2019-20924
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2019-20925
Risk: High
– Vulnerability in MongoDB Server - CVE-2019-2390
Risk: High
– Vulnerability in MongoDB Server - CVE-2019-2392
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2019-2393
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2020-7921
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2020-7923
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2020-7925
Risk: High
– Vulnerability in MongoDB Server - CVE-2020-7926
Risk: Medium
– Vulnerability in MongoDB Server - CVE-2020-7928
Risk: Medium
MySQL
– Critical Patch Update - January 2021
Risk: High
Oracle
– Critical Patch Update/Patch Set Update - January 2021
Risk: High
PostgreSQL
– Vulnerability in PostgreSQL client - CVE-2018-1053
Risk: Medium
– Vulnerability in PostgreSQL client - CVE-2018-1058
Risk: High
– Vulnerability in PostgreSQL client - CVE-2018-10915
Risk: High
– Vulnerability in PostgreSQL client - CVE-2020-25694
Risk: High
– Vulnerability in PostgreSQL client - CVE-2020-25696
Risk: High
– Vulnerability in PostgreSQL contrib module - CVE-2018-1115
Risk: Medium
– Vulnerability in PostgreSQL core server - CVE-2018-1052
Risk: Medium
– Vulnerability in PostgreSQL core server - CVE-2018-10925
Risk: High
– Vulnerability in PostgreSQL core server - CVE-2018-16850
Risk: High
– Vulnerability in PostgreSQL core server - CVE-2019-10129
Risk: Medium
– Vulnerability in PostgreSQL core server - CVE-2019-10130
Risk: Medium
– Vulnerability in PostgreSQL core server - CVE-2019-10164
Risk: High
– Vulnerability in PostgreSQL core server - CVE-2019-10208
Risk: High
– Vulnerability in PostgreSQL core server - CVE-2019-10209
Risk: Low
– Vulnerability in PostgreSQL core server - CVE-2020-14349
Risk: High
– Vulnerability in PostgreSQL core server - CVE-2020-14350
Risk: High
– Vulnerability in PostgreSQL core server - CVE-2020-1720
Risk: Low
– Vulnerability in PostgreSQL core server - CVE-2020-25695
Risk: High
– Vulnerability in PostgreSQL packaging - CVE-2019-10127
Risk: High
– Vulnerability in PostgreSQL packaging - CVE-2019-10128
Risk: High
– Vulnerability in PostgreSQL packaging - CVE-2019-10210
Risk: Medium
– Vulnerability in PostgreSQL packaging - CVE-2019-10211
Risk: High
– Vulnerability in PostgreSQL packaging - CVE-2019-3466
Risk: High
– Vulnerability in PostgreSQL packaging - CVE-2020-10733
Risk: Medium
Microsoft SQL Server
MySQL