V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2012-5627
DEB
LowConfirmedExploit available

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executi…

CVSS
2.6
Low
EPSS
0.04
p88
Published
2012-01-01
Updated
2012-01-01
Description

Oracle MySQL and MariaDB 5.5.x before 5.5.29, 5.3.x before 5.3.12, and 5.2.x before 5.2.14 does not modify the salt during multiple executions of the change_user command within the same connection which makes it easier for remote authenticated users to conduct brute force password guessing attacks.

Tags · CWE
CWE-522
CAPEC-50
CAPEC-102
CAPEC-474
CAPEC-509
CAPEC-551
CAPEC-555
CAPEC-560
CAPEC-561
CAPEC-600
CAPEC-644
CAPEC-645
CAPEC-652
CAPEC-653
Affected products
Mariadb 5.2.0–5.2.14Mariadb 5.3.0–5.3.12Mariadb 5.5.0–5.5.29Mariadb
CVSS vector
AV:N/AC:H/Au:N/C:P/I:N/A:N
Timeline
2012-01-01
Published
2012-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Authentication
Au: N
None (N)
Confidentiality Impact
C: P
Partial
Integrity Impact
I: N
None (N)
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.039 · p88
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-555 · CWE-522
└ via CAPEC-561 · CWE-522
└ via CAPEC-560 · CWE-522
└ via CAPEC-600 · CWE-522
└ via CAPEC-555 · CWE-522
└ via CAPEC-555 · CWE-522
└ via CAPEC-551 · CWE-522
└ via CAPEC-644 · CWE-522
└ via CAPEC-645 · CWE-522
└ via CAPEC-474 · CWE-522
└ via CAPEC-652 · CWE-522
└ via CAPEC-509 · CWE-522
Known exploits — Сканер-ВС
38109
exploitdb · https://www.exploit-db.com/exploits/38109
Enterprise
Affected software
ProductVendorStatus
mariadb-5.5Tracked
mariadb-5.5Tracked
mariadb-5.5Tracked
mysql-5.1Tracked
mysql-5.5Tracked
mysql-5.5Tracked
mysql-5.5Tracked
mysql-5.6Tracked
mysql-5.6Tracked
mysql-5.6Tracked
mysql-5.6Tracked
mariadb*Tracked
mysql*Tracked
Source databases
DEB
CVE
UBU