CVE-2014-4987: Medium severity suse linux vulnerability
serverusergroups.php in phpMyAdmin 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6 allows remote authenticated users to bypass intended access restrictions and read the MySQL user list via a viewUsers request.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4987?
CVE-2014-4987 is classified as a medium severity vulnerability that allows authenticated users to bypass access controls in phpMyAdmin.
How do I fix CVE-2014-4987?
To mitigate CVE-2014-4987, users should upgrade phpMyAdmin to version 4.1.14.2 or later, or 4.2.6 or later.
Which software versions are affected by CVE-2014-4987?
CVE-2014-4987 affects phpMyAdmin versions 4.1.x before 4.1.14.2 and 4.2.x before 4.2.6.
What type of access can be exploited due to CVE-2014-4987?
CVE-2014-4987 allows remote authenticated users to read the MySQL user list by bypassing intended access restrictions.
Is there a specific setting that could be temporarily adjusted to limit exposure for CVE-2014-4987?
While waiting for an update, limiting the scope of user privileges in MySQL can reduce exposure to CVE-2014-4987.