CVE Vulnerabilities

CVE-2016-0898

Published: Mar 29, 2018 | Modified: Nov 21, 2024
CVSS 3.x
10
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.

Affected Software

NameVendorStart VersionEnd Version
Pivotal_software_mysqlVmware1.7.0 (including)1.7.0 (including)
Pivotal_software_mysqlVmware1.7.0.1 (including)1.7.0.1 (including)
Pivotal_software_mysqlVmware1.7.0.2 (including)1.7.0.2 (including)
Pivotal_software_mysqlVmware1.7.0.3 (including)1.7.0.3 (including)
Pivotal_software_mysqlVmware1.7.0.4 (including)1.7.0.4 (including)
Pivotal_software_mysqlVmware1.7.1 (including)1.7.1 (including)
Pivotal_software_mysqlVmware1.7.2 (including)1.7.2 (including)
Pivotal_software_mysqlVmware1.7.3 (including)1.7.3 (including)
Pivotal_software_mysqlVmware1.7.4 (including)1.7.4 (including)
Pivotal_software_mysqlVmware1.7.5 (including)1.7.5 (including)
Pivotal_software_mysqlVmware1.7.6 (including)1.7.6 (including)
Pivotal_software_mysqlVmware1.7.7 (including)1.7.7 (including)
Pivotal_software_mysqlVmware1.7.8 (including)1.7.8 (including)
Pivotal_software_mysqlVmware1.7.9 (including)1.7.9 (including)

References