Security Advisory

CVE-2015-1027

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-09-28 19:00:00
Last updated 2024-08-06 04:33:19
Assigner mitre
CVSS score not scored
State PUBLISHED

Description

The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.