CVE-2016-9850: Medium severity phpmyadmin vulnerability
An issue was discovered in phpMyAdmin. Username matching for the allow/deny rules may result in wrong matches and detection of the username in the rule due to non-constant execution time. All 4.6.x versions (prior to 4.6.5), 4.4.x versions (prior to 4.4.15.9), and 4.0.x versions (prior to 4.0.10.18) are affected.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2016-9850?
CVE-2016-9850 is considered to have a moderate severity level due to the potential for username matching issues in phpMyAdmin.
How do I fix CVE-2016-9850?
To fix CVE-2016-9850, upgrade to phpMyAdmin version 4.6.5 or later for 4.6.x, 4.4.15.9 or later for 4.4.x, and 4.0.10.18 or later for 4.0.x.
Which versions of phpMyAdmin are affected by CVE-2016-9850?
CVE-2016-9850 affects phpMyAdmin versions 4.6.0 to 4.6.4, 4.4.0 to 4.4.15.8, and 4.0.0 to 4.0.10.17.
What kind of vulnerability is CVE-2016-9850?
CVE-2016-9850 is a vulnerability related to improper username matching which can lead to unauthorized access or manipulation.
Is there a workaround for CVE-2016-9850?
There is no official workaround for CVE-2016-9850; the recommended solution is to upgrade to the patched versions.