CVE-2015-1027
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.
La subrutina de chequeo de versiones en percona-toolkit en versiones anteriores a la 2.2.13 y xtrabackup en versiones anteriores a la 2.2.9 era vulnerable a ataques silenciosos de degradación HTTP y Man-in-the-Middle (MitM) en los que la respuesta del servidor se podría modificar para que permita que el atacante responda con una carga útil de comandos modificada y fuerce a que el cliente devuelva información adicional de la configuración que se está ejecutando, lo cual provocaría la revelación de información de la configuración actual de MySQL.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2015-01-10 CVE Reserved
- 2017-09-28 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-06 CVE Updated
- 2024-08-06 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://bugs.launchpad.net/percona-toolkit/+bug/1408375 | Issue Tracking |
URL | Date | SRC |
---|---|---|
https://www.percona.com/blog/2015/05/06/percona-security-advisory-cve-2015-1027 | 2024-08-06 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Percona Search vendor "Percona" | Toolkit Search vendor "Percona" for product "Toolkit" | <= 2.2.12 Search vendor "Percona" for product "Toolkit" and version " <= 2.2.12" | - |
Affected
| ||||||
Percona Search vendor "Percona" | Xtrabackup Search vendor "Percona" for product "Xtrabackup" | <= 2.2.8 Search vendor "Percona" for product "Xtrabackup" and version " <= 2.2.8" | - |
Affected
|