CVE-2015-1027
Last modified
CVE-2015-1027 is a vulnerability of currently unknown severity. The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
The version checking subroutine in percona-toolkit before 2.2.13 and xtrabackup before 2.2.9 was vulnerable to silent HTTP downgrade attacks and Man In The Middle attacks in which the server response could be modified to allow the attacker to respond with modified command payload and have the client return additional running configuration information leading to an information disclosure of running configuration of MySQL.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Percona | Toolkit | <= 2.2.12 |
| Percona | Xtrabackup | <= 2.2.8 |
References
- https://bugs.launchpad.net/percona-toolkit/+bug/1408375Issue Tracking, Third Party Advisory
- https://www.percona.com/blog/2015/05/06/percona-security-advisory-cve-2015-1027/Exploit, Mitigation, Vendor Advisory
- https://bugs.launchpad.net/percona-toolkit/+bug/1408375Issue Tracking, Third Party Advisory
- https://www.percona.com/blog/2015/05/06/percona-security-advisory-cve-2015-1027/Exploit, Mitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2015-1027?
How severe is CVE-2015-1027?
How do I fix CVE-2015-1027?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2015
- CVE-2015-10145Gargoyle router management utility versions 1.5.x contain an…8.8
- CVE-2015-10146The Thumbnail Slider With Lightbox plugin for WordPress is v…4.9
- CVE-2015-10147The Easy Testimonial Slider and Form plugin for WordPress is…4.9
- CVE-2015-10148Hirschmann HiLCOS devices OpenBAT, WLC, BAT300, BAT54 prior …8.8
- CVE-2015-1015Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices befo…
- CVE-2015-1026Multiple cross-site scripting (XSS) vulnerabilities in ZOHO …
- CVE-2015-1028Multiple cross-site scripting (XSS) vulnerabilities in D-Lin…
- CVE-2015-1029The puppetlabs-stdlib module 2.1 through 3.0 and 4.1.0 throu…
- CVE-2015-1030Memory leak in the rfc2553_connect_to function in jbsocket.c…
- CVE-2015-1031Multiple use-after-free vulnerabilities in Privoxy before 3.…
- CVE-2015-1032Cross-site scripting (XSS) vulnerability in Kiwix before 0.9…
- CVE-2015-1038p7zip 9.20.1 allows remote attackers to write to arbitrary f…
Are you affected by CVE-2015-1027?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
