We have the same issue and need to upgrade all version of PostgreSQL to the latest patch. This would be 9.4.24 for PostgreSQL 9.4.x. (https://www.postgresql.org/about/news/1960/)
Is the bundled version of PostgreSQL susceptible to the latest security vulnerabilities (CVE-2019-10200 to CVE-2019-102011)? And if so, is Cisco addressing this with an updated DCNM release? Or can we just upgrade the bundled PostgreSQL in place?
Thanks,
Peter.