# PostgreSQL PL/Java CVE-2016-0768, CVE-2016-0767, CVE-2016-2192

**URL:** https://www.finalbuilder.com/forums/t/postgresql-pl-java-cve-2016-0768-cve-2016-0767-cve-2016-2192/5653
**Category:** Discussion
**Created:** [July 17, 2017, 5:00am UTC](https://www.finalbuilder.com/forums/t/postgresql-pl-java-cve-2016-0768-cve-2016-0767-cve-2016-2192/5653 "2017-07-17T05:00:51Z")
**Posts on this page:** 2
**Page:** 1

<div class="post-metadata">

### Author: ![braindead](https://www.finalbuilder.com/forums/letter_avatar_proxy/v4/letter/b/6f9a4e/32.png) [@braindead](https://www.finalbuilder.com/forums/u/braindead)
#### Post date: [July 17, 2017, 5:00am UTC](https://www.finalbuilder.com/forums/t/postgresql-pl-java-cve-2016-0768-cve-2016-0767-cve-2016-2192/5653/1 "2017-07-17T05:00:51Z")

</div>

There are 3 reported vulnerabilities for PostgreSQL (see subject for CVE numbers)  
  
All are related to PL/Java, I’m not sure what’s included in the bundled installation of PostgreSQL.&nbsp; It appears that the installation is only listening on 127.0.0.1, so perhaps that in itself mitigates most of the possible risks.&nbsp; is PL/Java included in the installation?

---

<div class="post-metadata">

### Author: ![Vincent](https://www.finalbuilder.com/forums/user_avatar/www.finalbuilder.com/vincent/32/938_2.png) [@Vincent](https://www.finalbuilder.com/forums/u/Vincent)
#### Post date: [July 18, 2017, 2:30am UTC](https://www.finalbuilder.com/forums/t/postgresql-pl-java-cve-2016-0768-cve-2016-0767-cve-2016-2192/5653/2 "2017-07-18T02:30:57Z")

</div>

Hi   
  
 I took a look at the CVE’s, however they do not apply to our use of Postgresql. We don’t use PL/Java at all, and yes, we do bind the service to 127.0.0.1 only to avoid other non local programs connecting to the instance.   
  
 Thanks for reporting them anyway, we’re always keen to make sure we do not leave our customers exposed.
