CVE-2016-0898
Summary
| CVE | CVE-2016-0898 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-03-29 22:29:00 UTC |
| Updated | 2021-09-09 17:33:00 UTC |
| Description | MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM. |
Risk And Classification
Problem Types: CWE-255 | CWE-532
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Mysql | 1.7.0 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.1 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.2 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.3 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.4 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.1 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.2 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.3 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.4 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.5 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.6 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.7 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.8 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.9 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.1 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.2 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.3 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.0.4 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.1 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.2 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.3 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.4 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.5 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.6 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.7 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.8 | All | All | All |
| Application | Pivotal Software | Mysql | 1.7.9 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.0 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.0.1 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.0.2 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.0.3 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.0.4 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.1 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.2 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.3 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.4 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.5 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.6 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.7 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.8 | All | All | All |
| Application | Vmware | Pivotal Software Mysql | 1.7.9 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2016-0898 Service backups log AWS key | Security | Pivotal | CONFIRM | pivotal.io | Vendor Advisory |
| Pivotal MySQL for PCF CVE-2016-0898 Information Disclosure Vulnerability | BID | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.