Multiple vulnerabilities in MySQL Enterprise Monitor



Published: 2021-01-20
Risk Medium
Patch available YES
Number of vulnerabilities 3
CVE ID CVE-2020-5408
CVE-2020-5421
CVE-2019-10086
CWE ID CWE-330
CWE-20
CWE-693
Exploitation vector Network
Public exploit Public exploit code for vulnerability #2 is available.
Vulnerable software
Subscribe
MySQL Enterprise Monitor
Server applications / Database software

Vendor Oracle

Security Advisory

1) Use of insufficiently random values

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2020-5408

CWE-ID: CWE-330 - Use of Insufficiently Random Values

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to the affected software uses a fixed null initialization vector with CBC Mode in the implementation of the queryable text encryptor. A remote authenticated attacker can derive the unencrypted values using a dictionary attack.

Mitigation

Install update from vendor's website.

Vulnerable software versions

MySQL Enterprise Monitor: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.14, 8.0.16, 8.0.17, 8.0.18, 8.0.18.1217, 8.0.20, 8.0.21, 8.0.22

CPE External links

https://www.oracle.com/security-alerts/cpujan2021.html?61473

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Improper input validation

Risk: Medium

CVSSv3.1: 5.7 [CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:C/C:L/I:H/A:N/E:U/RL:O/RC:C] [PCI]

CVE-ID: CVE-2020-5421

CWE-ID: CWE-20 - Improper Input Validation

Exploit availability: Yes

Description

The vulnerability allows a remote authenticated user to read and manipulate data.

The vulnerability exists due to improper input validation within the Core (Spring Framework) component in Oracle Communications Session Report Manager. A remote authenticated user can exploit this vulnerability to read and manipulate data.

Mitigation

Install update from vendor's website.

Vulnerable software versions

MySQL Enterprise Monitor: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.14, 8.0.16, 8.0.17, 8.0.18, 8.0.18.1217, 8.0.20, 8.0.21, 8.0.22

CPE External links

https://www.oracle.com/security-alerts/cpujan2021.html?61473

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Protection mechanism failure

Risk: Low

CVSSv3.1: 3.2 [CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C]

CVE-ID: CVE-2019-10086

CWE-ID: CWE-693 - Protection Mechanism Failure

Exploit availability: No

Description

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exist due to Beanutils is not using by default the a special BeanIntrospector class in PropertyUtilsBean that was supposed to suppress the ability for an attacker to access the classloader via the class property available on all Java objects. A remote attacker can abuse such application behavior against applications that were developed to rely on this security feature.

Mitigation

Install update from vendor's website.

Vulnerable software versions

MySQL Enterprise Monitor: 8.0.0, 8.0.1, 8.0.2, 8.0.3, 8.0.14, 8.0.16, 8.0.17, 8.0.18, 8.0.18.1217, 8.0.20, 8.0.21, 8.0.22

CPE External links

https://www.oracle.com/security-alerts/cpujan2021.html?61473

Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

How the attacker can exploit this vulnerability?

The attacker would have to send a specially crafted request to the affected application in order to exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###