Lucene search

K
cvelistOracleCVELIST:CVE-2018-3123
HistoryApr 23, 2019 - 6:16 p.m.

CVE-2018-3123

2019-04-2318:16:38
oracle
www.cve.org

5.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.8%

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: libmysqld). Supported versions that are affected are 5.6.42 and prior, 5.7.24 and prior and 8.0.13 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).

CNA Affected

[
  {
    "product": "MySQL Server",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "5.6.42 and prior"
      },
      {
        "status": "affected",
        "version": "5.7.24 and prior"
      },
      {
        "status": "affected",
        "version": "8.0.13 and prior"
      }
    ]
  }
]

5.4 Medium

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

58.8%