PT-2020-18477 · Mysql Server+1 · Mysql Server+1
Published
2020-11-11
·
Updated
2020-12-01
·
CVE-2020-5426
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Scheduler for TAS versions prior to 1.4.0
Description
The issue allows plaintext transmission of a UAA client token over a non-TLS connection, which depends on the configuration of the MySQL server used to cache the token. If the token is intercepted, it can provide an attacker with admin-level access in the cloud controller.
Recommendations
For versions prior to 1.4.0, update to version 1.4.0 or later to resolve the issue. As a temporary workaround, consider configuring the MySQL server to use a secure connection or restricting access to the UAA client token to minimize the risk of exploitation.
Fix
Cleartext Transmission of Sensitive Information
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mysql Server
Scheduler For Tas