Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.112199
Category:Databases
Title:MariaDB Access Bypass Vulnerability - Windows
Summary:MariaDB is prone to an access bypass vulnerability.
Description:Summary:
MariaDB is prone to an access bypass vulnerability.

Vulnerability Insight:
sql/event_data_objects.cc in MariaDB allows remote authenticated users with SQL access
to bypass intended access restrictions and replicate data definition language (DDL) statements to cluster nodes by leveraging incorrect ordering of DDL replication and ACL checking.

Vulnerability Impact:
A user with an SQL access to the server could possibly use this flaw
to perform database modification on certain cluster nodes without having privileges to perform such changes.

Affected Software/OS:
MariaDB before 10.1.30 and 10.2.x before 10.2.10.

Solution:
Update to MariaDB 10.1.30, 10.2.10 or later.

CVSS Score:
6.5

CVSS Vector:
AV:N/AC:L/Au:S/C:P/I:P/A:P

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2017-15365
Debian Security Information: DSA-4341 (Google Search)
https://www.debian.org/security/2018/dsa-4341
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ELCZV46WIYSJ6VMC65GMNN3A3QDRUJGK/
RedHat Security Advisories: RHSA-2019:1258
https://access.redhat.com/errata/RHSA-2019:1258
CopyrightCopyright (C) 2018 Greenbone Networks GmbH

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.