« Back to list

CVE-2012-5615

Status: ModifiedMedium (5)—💥 Exploit

Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

💥 Public exploits

Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.

Affected technologies (2)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2012-5615",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "secalert@redhat.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2012-12-03T12:49:43.830",
  "references": [
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2012/Dec/9",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://secunia.com/advisories/53372",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201308-06.xml",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:102",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/12/02/3",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/12/02/4",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html",
      "source": "secalert@redhat.com"
    },
    {
      "url": "https://mariadb.atlassian.net/browse/MDEV-3909",
      "source": "secalert@redhat.com"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00000.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00016.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://seclists.org/fulldisclosure/2012/Dec/9",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/53372",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201308-06.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.mandriva.com/security/advisories?name=MDVSA-2013:102",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/12/02/3",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2012/12/02/4",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/bulletinoct2015-2511968.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.oracle.com/technetwork/topics/security/cpuoct2014-1972960.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://mariadb.atlassian.net/browse/MDEV-3909",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-200"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Oracle MySQL 5.5.38 and earlier, 5.6.19 and earlier, and MariaDB 5.5.28a, 5.3.11, 5.2.13, 5.1.66, and possibly other versions, generates different error messages with different time delays depending on whether a user name exists, which allows remote attackers to enumerate valid usernames."
    },
    {
      "lang": "es",
      "value": "MySQL v5.5.19 y posiblemente otras versiones, y MariaDB v5.5.28a, v5.3.11, v5.2.13, v5.1.66, y posiblemente con otras versiones, generan mensajes de error diferentes con retardos de tiempo diferentes dependiendo de si existe un nombre de usuario, lo que permite atacantes remotos para enumerar los nombres de usuario válidos."
    }
  ],
  "lastModified": "2026-06-16T23:47:05.720",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:mariadb:mariadb:5.1.66:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3CCF3D67-FAE6-43F4-B546-C7B46992251E"
            },
            {
              "criteria": "cpe:2.3:a:mariadb:mariadb:5.2.13:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "62C9A610-F5D7-4DAF-BB63-F062FB48210B"
            },
            {
              "criteria": "cpe:2.3:a:mariadb:mariadb:5.3.11:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DE70C2FA-7E45-4676-A15E-6D07BB97D937"
            },
            {
              "criteria": "cpe:2.3:a:mariadb:mariadb:5.5.28a:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "46E32ACD-E034-4FD6-A54A-43AFDA1AA196"
            },
            {
              "criteria": "cpe:2.3:a:oracle:mysql:5.5.19:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "77E105E9-FE65-4B75-9818-D3897294E941"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert@redhat.com"
}