10

CVE-2016-0898

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VMware ≫ Pivotal Software Mysql Version 1.7.0 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.0.1 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.0.2 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.0.3 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.0.4 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.1 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.2 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.3 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.4 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.5 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.6 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.7 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.8 SwPlatform pcf_tiles
VMware ≫ Pivotal Software Mysql Version 1.7.9 SwPlatform pcf_tiles
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.41% 0.693
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 3.9 6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
NIST 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
CWE-532 Insertion of Sensitive Information into Log File

The product writes sensitive information to a log file.

http://www.securityfocus.com/bid/95146
Third Party Advisory
VDB Entry
https://pivotal.io/security/cve-2016-0898
Vendor Advisory