Vulnerability Name:

CVE-2019-18622 (CCN-172224)

Assigned:2019-10-28
Published:2019-10-28
Updated:2020-01-14
Summary:An issue was discovered in phpMyAdmin before 4.9.2. A crafted database/table name can be used to trigger a SQL injection attack through the designer feature.
CVSS v3 Severity:9.8 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
8.5 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): High
Integrity (I): High
Availibility (A): High
6.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N)
5.7 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:7.5 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): Partial
6.4 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-89
Vulnerability Consequences:Data Manipulation
References:Source: MITRE
Type: CNA
CVE-2019-18622

Source: SUSE
Type: Mailing List, Third Party Advisory
openSUSE-SU-2019:2599

Source: SUSE
Type: UNKNOWN
openSUSE-SU-2020:0056

Source: XF
Type: UNKNOWN
phpmyadmin-cve201918622-sql-injection(172224)

Source: CCN
Type: PHPMyAdmin GitHub repository
Security patch for Designer and Designer visual mode

Source: FEDORA
Type: Third Party Advisory
FEDORA-2019-8f55b515f1

Source: FEDORA
Type: Third Party Advisory
FEDORA-2019-db68ae1fca

Source: GENTOO
Type: UNKNOWN
GLSA-202003-39

Source: CCN
Type: phpMyAdmin Security Advisory PMASA-2019-5
SQL injection in Designer feature

Source: CONFIRM
Type: Patch, Vendor Advisory
https://www.phpmyadmin.net/security/PMASA-2019-5/

Vulnerable Configuration:Configuration 1:
  • cpe:/a:phpmyadmin:phpmyadmin:*:*:*:*:*:*:*:* (Version < 4.9.2)

  • Configuration 2:
  • cpe:/a:opensuse:backports_sle:15.0:-:*:*:*:*:*:*
  • OR cpe:/a:opensuse:backports_sle:15.0:sp1:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:30:*:*:*:*:*:*:*
  • OR cpe:/o:fedoraproject:fedora:31:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.0:*:*:*:*:*:*:*
  • OR cpe:/o:opensuse:leap:15.1:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201918622
    V
    CVE-2019-18622
    2022-06-30
    oval:org.opensuse.security:def:93487
    P
    (Important)
    2022-03-10
    oval:org.opensuse.security:def:113142
    P
    phpMyAdmin-5.1.1-1.2 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:64586
    P
    Security update for systemd (Moderate)
    2021-10-12
    oval:org.opensuse.security:def:106570
    P
    phpMyAdmin-5.1.1-1.2 on GA media (Moderate)
    2021-10-01
    oval:org.opensuse.security:def:63220
    P
    libupsclient1-2.7.4-4.72 on GA media (Moderate)
    2021-09-21
    oval:org.opensuse.security:def:64756
    P
    Security update for gstreamer-plugins-good (Moderate)
    2021-09-02
    oval:org.opensuse.security:def:63332
    P
    gtk-vnc-devel-1.0.0-2.35 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:63358
    P
    nginx-1.19.8-1.1 on GA media (Moderate)
    2021-08-10
    oval:org.opensuse.security:def:62833
    P
    typelib-1_0-JavaScriptCore-4_0-2.32.0-3.15.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62829
    P
    sane-backends-1.0.32-6.6.2 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62739
    P
    evince-3.34.2-1.115 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63018
    P
    jython-2.2.1-11.65 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:63039
    P
    perl-solv-0.7.19-3.20.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:62836
    P
    wavpack-5.4.0-4.9.1 on GA media (Moderate)
    2021-08-09
    oval:org.opensuse.security:def:100308
    P
    (Important)
    2021-07-14
    oval:org.opensuse.security:def:63535
    P
    gegl-0_3-0.3.34-1.30 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:62861
    P
    libtool-32bit-2.4.6-1.406 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:74347
    P
    Security update for avahi (Moderate)
    2021-05-04
    oval:org.opensuse.security:def:64484
    P
    Security update for samba (Important)
    2021-04-29
    oval:org.opensuse.security:def:74698
    P
    Security update for velocity (Important)
    2021-03-16
    oval:org.opensuse.security:def:93595
    P
    (Important)
    2021-02-11
    oval:org.opensuse.security:def:64644
    P
    Security update for subversion (Important)
    2021-02-10
    oval:org.opensuse.security:def:63584
    P
    libgadu-devel-1.12.2-1.44 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62538
    P
    libXcursor1-32bit-1.1.15-1.18 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62562
    P
    libmad-devel-0.15.1b-3.16 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:62539
    P
    libXi6-32bit-1.7.9-1.23 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:25791
    P
    Security update for kernel-source (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25023
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:64253
    P
    freetype2-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25059
    P
    Security update for apache2-mod_auth_openidc (Important)
    2020-12-01
    oval:org.opensuse.security:def:64045
    P
    Security update for tomcat (Important)
    2020-12-01
    oval:org.opensuse.security:def:26458
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25835
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:25087
    P
    Security update for strongswan (Important)
    2020-12-01
    oval:org.opensuse.security:def:64295
    P
    libQt5Concurrent-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25060
    P
    Security update for libssh2_org (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64377
    P
    libqpdf21 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64240
    P
    dnsmasq on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63682
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26473
    P
    Security update for Chromium (Important)
    2020-12-01
    oval:org.opensuse.security:def:25214
    P
    Security update for transfig (Low)
    2020-12-01
    oval:org.opensuse.security:def:64407
    P
    libxml2-2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25071
    P
    Security update for dpdk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:64376
    P
    libpython3_6m1_0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:63911
    P
    Security update for file-roller (Low)
    2020-12-01
    oval:org.opensuse.security:def:26508
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:25295
    P
    Security update for python-ipaddress (Important)
    2020-12-01
    oval:org.opensuse.security:def:25135
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:64151
    P
    Security update for ovmf (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25586
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:25352
    P
    Security update for LibVNCServer (Important)
    2020-12-01
    oval:org.opensuse.security:def:74473
    P
    Security update for phpMyAdmin (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25263
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:25727
    P
    Security update for libzypp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25639
    P
    Security update for libqt5-qtimageformats (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25436
    P
    Security update for libgcrypt (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25344
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25741
    P
    Security update for vino (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:25012
    P
    Security update for mariadb, mariadb-connector-c (Important)
    2020-12-01
    oval:org.opensuse.security:def:25636
    P
    Security update for libproxy (Important)
    2020-12-01
    oval:org.opensuse.security:def:25401
    P
    Security update for freetype2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:74831
    P
    Security update for phpMyAdmin (Important)
    2020-12-01
    oval:org.opensuse.security:def:25785
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25777
    P
    Security update for flash-player (Critical)
    2020-12-01
    oval:org.opensuse.security:def:25689
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:25485
    P
    Security update for cups (Important)
    2020-12-01
    oval:org.opensuse.security:def:26423
    P
    Security update for opencv (Important)
    2020-12-01
    oval:org.opensuse.security:def:100200
    P
    (Moderate)
    2020-07-03
    oval:org.opensuse.security:def:110493
    P
    Security update for phpMyAdmin (Important)
    2020-01-14
    oval:org.opensuse.security:def:110097
    P
    Security update for phpMyAdmin (Moderate)
    2019-12-01
    oval:com.ubuntu.disco:def:2019186220000000
    V
    CVE-2019-18622 on Ubuntu 19.04 (disco) - medium.
    2019-11-22
    oval:com.ubuntu.bionic:def:2019186220000000
    V
    CVE-2019-18622 on Ubuntu 18.04 LTS (bionic) - medium.
    2019-11-22
    oval:com.ubuntu.xenial:def:2019186220000000
    V
    CVE-2019-18622 on Ubuntu 16.04 LTS (xenial) - medium.
    2019-11-22
    BACK
    phpmyadmin phpmyadmin *
    opensuse backports sle 15.0
    opensuse backports sle 15.0 sp1
    fedoraproject fedora 30
    fedoraproject fedora 31
    opensuse leap 15.0
    opensuse leap 15.1