CVE Vulnerabilities

CVE-2017-15365

Published: Jan 25, 2018 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
8.8 MODERATE
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

sql/event_data_objects.cc in MariaDB before 10.1.30 and 10.2.x before 10.2.10 and Percona XtraDB Cluster before 5.6.37-26.21-3 and 5.7.x before 5.7.19-29.22-3 allows remote authenticated users with SQL access to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.

Affected Software

Name Vendor Start Version End Version
Fedora Fedoraproject 26 (including) 26 (including)
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-mariadb102-galera-0:25.3.25-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 6 RedHat rh-mariadb102-mariadb-1:10.2.22-1.el6 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb102-galera-0:25.3.25-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7 RedHat rh-mariadb102-mariadb-1:10.2.22-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat rh-mariadb102-galera-0:25.3.25-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUS RedHat rh-mariadb102-mariadb-1:10.2.22-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat rh-mariadb102-galera-0:25.3.25-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUS RedHat rh-mariadb102-mariadb-1:10.2.22-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat rh-mariadb102-galera-0:25.3.25-1.el7 *
Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUS RedHat rh-mariadb102-mariadb-1:10.2.22-1.el7 *
Mariadb-10.1 Ubuntu artful *
Mariadb-10.1 Ubuntu cosmic *
Mariadb-10.1 Ubuntu upstream *
Mariadb-10.1 Ubuntu zesty *
Mysql-5.7 Ubuntu artful *
Mysql-5.7 Ubuntu zesty *
Percona-server-5.6 Ubuntu artful *
Percona-server-5.6 Ubuntu esm-apps/xenial *
Percona-server-5.6 Ubuntu xenial *
Percona-server-5.6 Ubuntu zesty *
Percona-xtradb-cluster-5.5 Ubuntu trusty *
Percona-xtradb-cluster-5.6 Ubuntu artful *
Percona-xtradb-cluster-5.6 Ubuntu esm-apps/xenial *
Percona-xtradb-cluster-5.6 Ubuntu xenial *
Percona-xtradb-cluster-5.6 Ubuntu zesty *

References