← Back

CVE-2016-9013

nvd nist
Published: Dec 9, 2016Modified: May 6, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Django 1.8.x before 1.8.16, 1.9.x before 1.9.11, and 1.10.x before 1.10.3 use a hardcoded password for a temporary database user created when running tests with an Oracle database, which makes it easier for remote attackers to obtain access to the database server by leveraging failure to manually specify a password in the database settings TEST dictionary.

Affected (36)

1 product
Django
1 product
Ubuntu Linux
1 product
Fedora
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.10.1
Version 1.10.2
Version 1.10
Configuration B
4 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Version 16.04
Version 16.10
Configuration C
11 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.9.10
Version 1.9.1
Version 1.9.2
Version 1.9.3
Version 1.9.4
Version 1.9.5
Version 1.9.6
Version 1.9.7
Version 1.9.8
Version 1.9.9
Version 1.9
Configuration D
16 vulnerable
Vulnerable SoftwareAffected Versions
Djangoproject
Version 1.8.10
Version 1.8.11
Version 1.8.12
Version 1.8.13
Version 1.8.14
Version 1.8.15
Version 1.8.1
Version 1.8.2
Version 1.8.3
Version 1.8.4
Version 1.8.5
Version 1.8.6
Version 1.8.7
Version 1.8.8
Version 1.8.9
Version 1.8
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 24
Version 25

References (14)

Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Release NotesVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release NotesVendor Advisory

Timeline

No history available yet.