CVE-2016-0898: Critical severity vmware pivotal mysql vulnerability
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0898?
CVE-2016-0898 has a severity level classified as medium due to the exposure of AWS access keys in plaintext.
How does CVE-2016-0898 affect my MySQL for PCF installation?
CVE-2016-0898 specifically affects versions of MySQL for PCF tiles from 1.7.0 to 1.7.9, where AWS access keys are logged in plaintext.
How do I fix CVE-2016-0898?
To fix CVE-2016-0898, upgrade your MySQL for PCF installation to version 1.7.10 or later.
What versions are vulnerable to CVE-2016-0898?
Versions 1.7.0 through 1.7.9 of MySQL for PCF are vulnerable to CVE-2016-0898.
Are my AWS credentials safe from CVE-2016-0898?
While CVE-2016-0898 logs AWS access keys in plaintext, they are only exposed within the Service Backup component logs, not outside the VM.