Vulnerability Description
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vmware | Pivotal Software Mysql | 1.7.0 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/95146Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2016-0898Vendor Advisory
- http://www.securityfocus.com/bid/95146Third Party AdvisoryVDB Entry
- https://pivotal.io/security/cve-2016-0898Vendor Advisory
FAQ
What is CVE-2016-0898?
CVE-2016-0898 is a vulnerability with a CVSS score of 10.0 (CRITICAL). MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were no...
How severe is CVE-2016-0898?
CVE-2016-0898 has been rated CRITICAL with a CVSS base score of 10.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2016-0898?
Check the references section above for vendor advisories and patch information. Affected products include: Vmware Pivotal Software Mysql.