Credentials management in mysql - CVE-2016-0898

 

Credentials management in mysql - CVE-2016-0898

Published: March 30, 2018 / Updated: August 8, 2020


Vulnerability identifier: #VU37355
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2016-0898
CWE-ID: CWE-255
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.


Affected software

mysql

How to mitigate CVE-2016-0898

Install update from vendor's website.


External References

Related Security Bulletins