Vulnerability Name:

CVE-2019-12922 (CCN-167092)

Assigned:2019-06-13
Published:2019-06-13
Updated:2023-02-02
Summary:
CVSS v3 Severity:6.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
5.7 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N/E:U/RL:U/RC:R)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): High
Availibility (A): None
CVSS v2 Severity:5.8 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): Partial
6.8 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:C/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Complete
Availibility (A): None
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2019-12922

Source: cve@mitre.org
Type: Broken Link
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Exploit, Third Party Advisory, VDB Entry
cve@mitre.org

Source: cve@mitre.org
Type: Exploit, Mailing List, Third Party Advisory
cve@mitre.org

Source: XF
Type: UNKNOWN
phpmyadmin-cve201912922-csrf(167092)

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Patch, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: cve@mitre.org
Type: Mailing List, Third Party Advisory
cve@mitre.org

Source: CCN
Type: Packet Storm Security [09-13-2019]
phpMyAdmin 4.9.0.1 Cross Site Request Forgery

Source: CCN
Type: Full-Disclosure Mailing List, Fri, 13 Sep 2019 08:17:20 +0200
phpMyAdmin 4.9.0.1 - Cross-Site Request Forgery

Source: cve@mitre.org
Type: Exploit, Third Party Advisory, VDB Entry
cve@mitre.org

Source: EXPLOIT-DB
Type: EXPLOIT
Offensive Security Exploit Database [09-13-2019]

Source: CCN
Type: phpMyAdmin Security Advisory PMASA-2019-4
CSRF vulnerability in login form

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2019-12922

Vulnerable Configuration:Configuration CCN 1:
  • cpe:/a:phpmyadmin:phpmyadmin:4.9.0.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:93470
    P
    (Important)
    2022-07-11
    oval:org.opensuse.security:def:201912922
    V
    CVE-2019-12922
    2022-06-30
    oval:org.opensuse.security:def:113142
    P
    phpMyAdmin-5.1.1-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:74394
    P
    Security update for MozillaFirefox (Important)
    2021-12-10
    oval:org.opensuse.security:def:64586
    P
    Security update for systemd (Moderate)
    2021-10-12
    oval:org.opensuse.security:def:106570
    P
    phpMyAdmin-5.1.1-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:64756
    P
    Security update for gstreamer-plugins-good (Moderate)
    2021-09-02
    oval:org.opensuse.security:def:63332
    P
    gtk-vnc-devel-1.0.0-2.35 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63505
    P
    perl-32bit-5.26.1-15.87 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62833
    P
    typelib-1_0-JavaScriptCore-4_0-2.32.0-3.15.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62829
    P
    sane-backends-1.0.32-6.6.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63039
    P
    perl-solv-0.7.19-3.20.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62836
    P
    wavpack-5.4.0-4.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100308
    P
    (Important)
    2021-07-14
    oval:org.opensuse.security:def:63535
    P
    gegl-0_3-0.3.34-1.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62861
    P
    libtool-32bit-2.4.6-1.406 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:64484
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:74698
    P
    Security update for velocity (Important)
    2021-03-16
    oval:org.opensuse.security:def:93595
    P
    (Important)
    2021-02-11
    oval:org.opensuse.security:def:64644
    P
    Security update for subversion (Important)
    2021-02-10
    oval:org.opensuse.security:def:74268
    P
    Security update for openssh (Moderate)
    2020-12-09
    oval:org.opensuse.security:def:62459
    P
    libnm-gtk-devel-1.8.10-3.39 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62483
    P
    perl-CGI-4.38-1.17 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62660
    P
    libass-devel-0.14.0-1.25 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62460
    P
    libopenjpeg1-1.5.2-2.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62939
    P
    build-20200124.1-1.21 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63141
    P
    apache2-mod_jk-1.2.43-1.36 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:63279
    P
    librelp-devel-1.2.15-1.15 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25735
    P
    Security update for exiv2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25017
    P
    Security update for ceph (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25059
    P
    Security update for apache2-mod_auth_openidc (Important)
    2020-12-01
    oval:org.opensuse.security:def:25636
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:74831
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:25779
    P
    Security update for the SUSE Linux Enterprise 12 kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25081
    P
    Security update for libarchive (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25777
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25060
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25689
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:63832
    P
    Security update for aspell (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63682
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26417
    P
    Security update for Mozilla Thunderbird (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25208
    P
    Security update for python3-requests (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25791
    P
    Security update for kernel-source (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25071
    P
    Security update for dpdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64174
    P
    Security update for java-1_7_0-openjdk (Important)
    2020-12-01
    oval:org.opensuse.security:def:63966
    P
    Security update for tigervnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:63911
    P
    Security update for file-roller (Low)
    2020-12-01
    oval:org.opensuse.security:def:26452
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25289
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25835
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25135
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64216
    P
    avahi on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64377
    P
    libqpdf21 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64240
    P
    dnsmasq on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25346
    P
    Security update for postgresql10 (Important)
    2020-12-01
    oval:org.opensuse.security:def:26473
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25263
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:64328
    P
    libgstgl-1_0-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64376
    P
    libpython3_6m1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25430
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:26508
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:25344
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64072
    P
    Security update for libsolv (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25006
    P
    Security update for apache-commons-beanutils (Important)
    2020-12-01
    oval:org.opensuse.security:def:25580
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:25401
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:25721
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25633
    P
    Security update for perl-DBI (Important)
    2020-12-01
    oval:org.opensuse.security:def:25485
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:110493
    P
    Security update for phpMyAdmin (Important)
    2020-01-14
    oval:org.opensuse.security:def:110018
    P
    Security update for phpMyAdmin (Moderate)
    2019-09-28
    oval:org.opensuse.security:def:100183
    P
    Security update for phpMyAdmin (Moderate)
    2019-09-28
    oval:com.ubuntu.disco:def:2019129220000000
    V
    CVE-2019-12922 on Ubuntu 19.04 (disco) - medium.
    2019-09-13
    oval:com.ubuntu.bionic:def:2019129220000000
    V
    CVE-2019-12922 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-09-13
    oval:com.ubuntu.xenial:def:2019129220000000
    V
    CVE-2019-12922 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-09-13
    BACK
    phpmyadmin phpmyadmin 4.9.0.1