First published: Sun Jul 20 2014(Updated: )
server_user_groups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SUSE Linux | =12.3 | |
SUSE Linux | =13.1 | |
phpMyAdmin | =4.1.0 | |
phpMyAdmin | =4.1.1 | |
phpMyAdmin | =4.1.2 | |
phpMyAdmin | =4.1.3 | |
phpMyAdmin | =4.1.4 | |
phpMyAdmin | =4.1.5 | |
phpMyAdmin | =4.1.6 | |
phpMyAdmin | =4.1.7 | |
phpMyAdmin | =4.1.8 | |
phpMyAdmin | =4.1.9 | |
phpMyAdmin | =4.1.10 | |
phpMyAdmin | =4.1.11 | |
phpMyAdmin | =4.1.12 | |
phpMyAdmin | =4.1.13 | |
phpMyAdmin | =4.1.14 | |
phpMyAdmin | =4.1.14.1 | |
phpMyAdmin | =4.2.0 | |
phpMyAdmin | =4.2.1 | |
phpMyAdmin | =4.2.2 | |
phpMyAdmin | =4.2.3 | |
phpMyAdmin | =4.2.4 | |
phpMyAdmin | =4.2.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-4987 is classified as a medium severity vulnerability that allows authenticated users to bypass access controls in phpMyAdmin.
To mitigate CVE-2014-4987, users should upgrade phpMyAdmin to version 4.1.14.2 or later, or 4.2.6 or later.
CVE-2014-4987 affects phpMyAdmin versions 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6.
CVE-2014-4987 allows remote authenticated users to read the MySQL user list by bypassing intended access restrictions.
While waiting for an update, limiting the scope of user privileges in MySQL can reduce exposure to CVE-2014-4987.