peter bassill · operator
$ cve CVE-2012-5615 JSON

CVE-2012-5615 EXPLOIT

5.0
MEDIUM · CVSS 2.0 · EPSS 14.8% (pctl 97)

Patch early

A public exploit exists.

Description

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

Scoring

CVSS5.0 (MEDIUM, v2.0)
VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS14.78% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-200
On CISA KEVno
Public exploityes
Published2012-12-03
Last modified2026-06-16

Affected (2)

VendorProduct
mariadbmariadb
oraclemysql

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD