Lucene search

K
cveOracleCVE-2017-10424
HistoryOct 19, 2017 - 5:29 p.m.

CVE-2017-10424

2017-10-1917:29:06
oracle
web.nvd.nist.gov
46
cve-2017-10424
mysql
oracle
enterprise monitor
vulnerability
cvss 3.0
compromise

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.004

Percentile

75.0%

Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Web). Supported versions that are affected are 3.2.8.2223 and earlier, 3.3.4.3247 and earlier and 3.4.2.4181 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise Monitor. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Enterprise Monitor. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Affected configurations

Nvd
Vulners
Node
oraclemysql_enterprise_monitorMatch3.2.0
OR
oraclemysql_enterprise_monitorMatch3.2.1
OR
oraclemysql_enterprise_monitorMatch3.2.2
OR
oraclemysql_enterprise_monitorMatch3.2.3
OR
oraclemysql_enterprise_monitorMatch3.2.4
OR
oraclemysql_enterprise_monitorMatch3.2.5
OR
oraclemysql_enterprise_monitorMatch3.2.6
OR
oraclemysql_enterprise_monitorMatch3.2.7
OR
oraclemysql_enterprise_monitorMatch3.2.8
OR
oraclemysql_enterprise_monitorMatch3.2.8.2223
Node
oraclemysql_enterprise_monitorMatch3.3.0
OR
oraclemysql_enterprise_monitorMatch3.3.1
OR
oraclemysql_enterprise_monitorMatch3.3.2
OR
oraclemysql_enterprise_monitorMatch3.3.3
OR
oraclemysql_enterprise_monitorMatch3.3.4
OR
oraclemysql_enterprise_monitorMatch3.3.4.3247
Node
oraclemysql_enterprise_monitorMatch3.4.0
OR
oraclemysql_enterprise_monitorMatch3.4.1
OR
oraclemysql_enterprise_monitorMatch3.4.2
OR
oraclemysql_enterprise_monitorMatch3.4.2.4181
VendorProductVersionCPE
oraclemysql_enterprise_monitor3.2.0cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.0:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.1cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.1:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.2cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.2:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.3cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.3:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.4cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.4:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.5cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.5:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.6cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.6:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.7cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.7:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.8cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.8:*:*:*:*:*:*:*
oraclemysql_enterprise_monitor3.2.8.2223cpe:2.3:a:oracle:mysql_enterprise_monitor:3.2.8.2223:*:*:*:*:*:*:*
Rows per page:
1-10 of 201

CNA Affected

[
  {
    "product": "MySQL Enterprise Monitor",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "3.2.8.2223 and earlier"
      },
      {
        "status": "affected",
        "version": "3.3.4.3247 and earlier"
      },
      {
        "status": "affected",
        "version": "3.4.2.4181 and earlier"
      }
    ]
  }
]

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

AI Score

7.9

Confidence

High

EPSS

0.004

Percentile

75.0%

Related for CVE-2017-10424