CVE-2015-2620Oracle Mysql vulnerability

8 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
0.8%
top 26.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 16
Latest updateMay 14

Description

Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.23 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Security : Privileges.

CVSS vector

AV:N/AC:M/C:P/I:N/A:NExploitability: 8.6 | Impact: 2.9

Affected Packages4 packages

NVDoracle/mysql5.5.05.5.43+1
NVDoracle/solaris11.3
NVDmariadb/mariadb5.5.05.5.44+1

Also affects: Debian Linux 8.0, Ubuntu Linux 12.04, 14.04, 14.10, 15.04

Patches

🔴Vulnerability Details

3
GHSA
GHSA-w97j-x2ff-rr4p: Unspecified vulnerability in Oracle MySQL Server 52022-05-14
OSV
CVE-2015-2620: Unspecified vulnerability in Oracle MySQL Server 52015-07-16
CVEList
CVE-2015-2620: Unspecified vulnerability in Oracle MySQL Server 52015-07-16

📋Vendor Advisories

2
Ubuntu
MySQL vulnerabilities2015-07-21
Red Hat
mysql: unspecified vulnerability related to Server:Security:Privileges (CPU July 2015)2015-07-14

💬Community

2
Bugzilla
CVE-2015-7502 CloudForms: insecure password storage in PostgreSQL database2015-11-18
Bugzilla
CVE-2015-2620 mysql: unspecified vulnerability related to Server:Security:Privileges (CPU July 2015)2015-07-20
CVE-2015-2620 — Oracle Mysql vulnerability | cvebase