| Vulnerability Name: | CVE-2016-0898 (CCN-143071) | ||||||||||||
| Assigned: | 2015-12-17 | ||||||||||||
| Published: | 2016-12-08 | ||||||||||||
| Updated: | 2021-09-09 | ||||||||||||
| Summary: | MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM. | ||||||||||||
| CVSS v3 Severity: | 10.0 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H) 8.7 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C)
6.5 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
| CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
| Vulnerability Type: | CWE-255 CWE-532 | ||||||||||||
| Vulnerability Consequences: | Obtain Information | ||||||||||||
| References: | Source: MITRE Type: CNA CVE-2016-0898 Source: BID Type: Third Party Advisory, VDB Entry 95146 Source: CCN Type: BID-95146 Pivotal MySQL for PCF CVE-2016-0898 Information Disclosure Vulnerability Source: XF Type: UNKNOWN pivotal-cve20160898-info-disc(143071) Source: CCN Type: Pivotal Web site CVE-2016-0898 Service backups log AWS key Source: CONFIRM Type: Vendor Advisory https://pivotal.io/security/cve-2016-0898 | ||||||||||||
| Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
| BACK | |||||||||||||