Vulnerabilities (CVE)

Filtered by vendor Tigergraph Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-28482 1 Tigergraph 1 Tigergraph 2023-08-21 N/A 6.5 MEDIUM
An issue was discovered in Tigergraph Enterprise 3.7.0. A single TigerGraph instance can host multiple graphs that are accessed by multiple different users. The TigerGraph platform does not protect the confidentiality of any data uploaded to the remote server. In this scenario, any user that has permissions to upload data can browse data uploaded by any other user (irrespective of their permissions).
CVE-2023-28480 1 Tigergraph 1 Tigergraph 2023-08-18 N/A 6.5 MEDIUM
An issue was discovered in Tigergraph Enterprise 3.7.0. The TigerGraph platform allows users to define new User Defined Functions (UDFs) from C/C++ code. To support this functionality TigerGraph allows users to upload custom C/C++ code which is then compiled and installed into the platform. An attacker who has filesystem access on a remote TigerGraph system can alter the behavior of the database against the will of the database administrator; thus effectively bypassing the built in RBAC controls.