Vulnerability Name:

CVE-2016-8647 (CCN-148465)

Assigned:2016-10-12
Published:2018-06-29
Updated:2023-02-12
Summary:
CVSS v3 Severity:4.9 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N)
4.3 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): High
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Consequences:Bypass Security
References:Source: MITRE
Type: CNA
CVE-2016-8647

Source: secalert@redhat.com
Type: Vendor Advisory
secalert@redhat.com

Source: CCN
Type: Red Hat Bugzilla – Bug 1396174
(CVE-2016-8647) CVE-2016-8647 Ansible: in some circumstances the mysql_user module may fail to correctly change a password

Source: secalert@redhat.com
Type: Issue Tracking, Vendor Advisory
secalert@redhat.com

Source: XF
Type: UNKNOWN
ansible-cve20168647-sec-bypass(148465)

Source: CCN
Type: ansible-modules-core GIT Repository
mysql_user: fix user_mod on MySQL(-like) 5.7+ (Fixes #3003) #5388

Source: secalert@redhat.com
Type: Third Party Advisory
secalert@redhat.com

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2016-8647

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:redhat:ansible:2.2.0.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20168647
    V
    CVE-2016-8647
    2022-05-22
    oval:org.opensuse.security:def:34050
    P
    Security update for java-1_8_0-ibm (Important) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:34011
    P
    Security update for MozillaFirefox (Important)
    2021-12-12
    oval:org.opensuse.security:def:34008
    P
    Security update for openssh (Important)
    2021-12-02
    oval:org.opensuse.security:def:33747
    P
    Security update for xen (Moderate)
    2021-12-01
    oval:org.opensuse.security:def:33744
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-11-23
    oval:org.opensuse.security:def:60340
    P
    Security update for openssl-1_1 (Important)
    2021-08-24
    oval:org.opensuse.security:def:33962
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:33959
    P
    Security update for java-1_8_0-openjdk (Important)
    2021-08-20
    oval:org.opensuse.security:def:33904
    P
    Security update for avahi (Important)
    2021-06-03
    oval:org.opensuse.security:def:33659
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:33901
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:30070
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:30067
    P
    Security update for gdm (Important)
    2021-04-28
    oval:org.opensuse.security:def:29351
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:29348
    P
    Security update for sudo (Important)
    2021-04-20
    oval:org.opensuse.security:def:34047
    P
    Security update for tomcat (Important)
    2021-03-30
    oval:org.opensuse.security:def:29482
    P
    Security update for wpa_supplicant (Important)
    2021-03-09
    oval:org.opensuse.security:def:29479
    P
    Security update for grub2 (Important)
    2021-03-02
    oval:org.opensuse.security:def:59856
    P
    Security update for python-cryptography (Important)
    2021-03-02
    oval:org.opensuse.security:def:60456
    P
    Security update for tomcat (Moderate)
    2021-02-19
    oval:org.opensuse.security:def:30026
    P
    Security update for bind (Important)
    2021-02-18
    oval:org.opensuse.security:def:30023
    P
    Security update for wpa_supplicant (Important)
    2021-02-15
    oval:org.opensuse.security:def:60300
    P
    Security update for postgresql, postgresql12, postgresql13 (Important)
    2021-01-26
    oval:org.opensuse.security:def:30007
    P
    Security update for ImageMagick (Important)
    2021-01-22
    oval:org.opensuse.security:def:30004
    P
    Security update for flac (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:33656
    P
    Security update for dovecot22 (Important)
    2021-01-04
    oval:org.opensuse.security:def:29965
    P
    Security update for cyrus-sasl (Important)
    2020-12-28
    oval:org.opensuse.security:def:61058
    P
    Security update for openexr (Moderate)
    2020-12-23
    oval:org.opensuse.security:def:33290
    P
    xen on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29919
    P
    Security update for libevent
    2020-12-01
    oval:org.opensuse.security:def:34757
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29266
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:29861
    P
    Security update for Linux Kernel
    2020-12-01
    oval:org.opensuse.security:def:34116
    P
    Security update for nautilus (Low)
    2020-12-01
    oval:org.opensuse.security:def:60111
    P
    Security update for the Linux Kernel (Live Patch 30 for SLE 12 SP2) (Important)
    2020-12-01
    oval:org.opensuse.security:def:33599
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:33371
    P
    Security update for compat-openssl097g
    2020-12-01
    oval:org.opensuse.security:def:60718
    P
    Security update for python3-requests (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30745
    P
    Security update for ansible, python-straight-plugin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29277
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:30705
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:29268
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:60937
    P
    Security update for galera-3, mariadb, mariadb-connector-c (Important)
    2020-12-01
    oval:org.opensuse.security:def:60634
    P
    Security update for openssl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33506
    P
    Security update for openslp
    2020-12-01
    oval:org.opensuse.security:def:60711
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29269
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:29864
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:34119
    P
    Security update for ncurses (Important)
    2020-12-01
    oval:org.opensuse.security:def:29708
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:34072
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33602
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34794
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29280
    P
    Security update for xorg-x11-libX11 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60600
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:30708
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:33275
    P
    tomcat6 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60041
    P
    Security update for bash (Important)
    2020-12-01
    oval:org.opensuse.security:def:60899
    P
    Security update for mariadb (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29566
    P
    Security update for OpenEXR (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60552
    P
    sysvinit-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60978
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:33276
    P
    unixODBC_23 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60761
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:29711
    P
    Security update for Mozilla Firefox
    2020-12-01
    oval:org.opensuse.security:def:34075
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29623
    P
    Security update for bsdtar (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29968
    P
    Security update for libproxy
    2020-12-01
    oval:org.opensuse.security:def:34797
    P
    Security update for ansible, python-straight-plugin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33287
    P
    x3270 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29916
    P
    Security update for libcroco (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34754
    P
    Security update for MozillaFirefox, mozilla-nss, mozilla-nspr (Important)
    2020-12-01
    oval:org.opensuse.security:def:33278
    P
    unzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29569
    P
    Security update for SDL (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:60815
    P
    Security update for python3 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33368
    P
    Security update for wget (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30742
    P
    Security update for ansible (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33279
    P
    vino on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:61028
    P
    Security update for java-1_8_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:29265
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:60672
    P
    Security update for python-PyKMIP (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29626
    P
    Security update for bzip2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:33503
    P
    Security update for nagios
    2020-12-01
    oval:org.opensuse.security:def:60790
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-12-01
    oval:org.opensuse.security:def:84056
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-11-12
    oval:org.opensuse.security:def:84511
    P
    Security update for ansible, ardana-ansible, ardana-cinder, ardana-glance, ardana-mq, ardana-nova, ardana-osconfig, crowbar-core, crowbar-openstack, documentation-suse-openstack-cloud, grafana, grafana-natel-discrete-panel, openstack-cinder, openstack-monasca-installer, openstack-neutron, openstack-nova, python-Django, python-Flask-Cors, python-Pillow, python-ardana-packager, python-keystoneclient, python-keystonemiddleware, python-kombu, python-straight-plugin, python-urllib3, release-notes-suse-openstack-cloud, storm, storm-kit, venv-openstack-cinder, venv-openstack-swift (Important)
    2020-11-12
    oval:com.ubuntu.bionic:def:201686470000000
    V
    CVE-2016-8647 on Ubuntu 18.04 LTS (bionic) - low.
    2018-07-26
    oval:com.ubuntu.xenial:def:20168647000
    V
    CVE-2016-8647 on Ubuntu 16.04 LTS (xenial) - low.
    2018-07-26
    oval:com.ubuntu.xenial:def:201686470000000
    V
    CVE-2016-8647 on Ubuntu 16.04 LTS (xenial) - low.
    2018-07-26
    oval:com.ubuntu.bionic:def:20168647000
    V
    CVE-2016-8647 on Ubuntu 18.04 LTS (bionic) - low.
    2018-07-26
    oval:com.ubuntu.disco:def:201686470000000
    V
    CVE-2016-8647 on Ubuntu 19.04 (disco) - low.
    2018-07-26
    oval:com.ubuntu.cosmic:def:20168647000
    V
    CVE-2016-8647 on Ubuntu 18.10 (cosmic) - low.
    2018-07-26
    oval:com.ubuntu.cosmic:def:201686470000000
    V
    CVE-2016-8647 on Ubuntu 18.10 (cosmic) - low.
    2018-07-26
    oval:com.ubuntu.trusty:def:20168647000
    V
    CVE-2016-8647 on Ubuntu 14.04 LTS (trusty) - low.
    2018-07-26
    oval:com.ubuntu.artful:def:20168647000
    V
    CVE-2016-8647 on Ubuntu 17.10 (artful) - low.
    2016-11-18
    BACK
    redhat ansible 2.2.0.0