CVE-2012-5615 PUBLISHED

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

EPSS 20.66% · 95.5th percentile

Risk Scores

EPSS Score
20.66%
95.5th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSmysql-5.60, 5.6.15-0ubuntu1, 5.6.15-1~exp2
Ubuntu:14.04:LTSmysql-5.55.5.37-0ubuntu0.14.04.1, 0, 5.5.38-0ubuntu0.14.04.1

Timeline

References

Open in Interactive Console →