Percona XtraBackup before 2.1.6 uses a constant string for the initialization vector (IV), which makes it easier for local users to defeat cryptographic protection mechanisms and conduct plaintext attacks.
{
"binaries": [
{
"binary_version": "2.1.8-1",
"binary_name": "percona-xtrabackup"
},
{
"binary_version": "2.1.8-1",
"binary_name": "percona-xtrabackup-dbg"
},
{
"binary_version": "2.1.8-1",
"binary_name": "percona-xtrabackup-test"
},
{
"binary_version": "2.1.8-1",
"binary_name": "xtrabackup"
}
],
"availability": "No subscription required"
}