Lucene search

K
kasperskyKaspersky LabKLA10794
HistoryApr 19, 2016 - 12:00 a.m.

KLA10794 Multiple vulnerabilities in Oracle MySQL

2016-04-1900:00:00
Kaspersky Lab
threats.kaspersky.com
55

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

Low

0.953 High

EPSS

Percentile

99.4%

An unspecified vulnerabilities were found in Oracle MySQL Server. By exploiting these vulnerabilities malicious users can cause denial of service and loss of integrity or obtain sensitive information. These vulnerabilities can be exploited remotely via a vectors related to Packaging, Pluggable Authentication, Security: Encryption, DML, Connection Handling, DDL, FTS, InnoDB, JSON, Optimizer, PS, Partition, Replication, Security: Privileges, MyISAM, Federated, Options, Performance Schema and Locking.

Original advisories

Oracle bulletin

Exploitation

Public exploits exist for this vulnerability.

Related products

Oracle-MySQL

CVE list

CVE-2016-2047 high

CVE-2016-0665 high

CVE-2016-0666 high

CVE-2016-0656 high

CVE-2016-0655 warning

CVE-2016-0654 high

CVE-2016-0653 high

CVE-2016-0652 high

CVE-2016-0651 high

CVE-2016-0650 high

CVE-2016-0649 high

CVE-2016-0658 high

CVE-2016-0657 high

CVE-2016-0647 high

CVE-2016-0705 critical

CVE-2016-0642 warning

CVE-2016-0643 warning

CVE-2016-0644 high

CVE-2016-0661 warning

CVE-2016-0667 warning

CVE-2016-0639 critical

CVE-2016-0640 high

CVE-2016-0641 high

CVE-2015-3194 critical

CVE-2016-0648 high

CVE-2016-0662 high

CVE-2016-0663 warning

CVE-2016-0659 high

CVE-2016-0646 high

CVE-2016-0668 warning

Solution

Update to the latest version

MySQL downloads

Impacts

  • ACE

Arbitrary code execution. Exploitation of vulnerabilities with this impact can lead to executing by abuser any code or commands at vulnerable machine or process.

  • OSI

Obtain sensitive information. Exploitation of vulnerabilities with this impact can lead to capturing by abuser information, critical for user or system.

  • DoS

Denial of service. Exploitation of vulnerabilities with this impact can lead to loss of system availability or critical functional fault.

  • SB

Security bypass. Exploitation of vulnerabilities with this impact can lead to performing actions restricted by current security settings.

  • LoI

Loss of integrity. Exploitation of vulnerabilities with this impact can lead to partial system fault or system components connection disruption.

Affected Products

  • Oracle MySQL Server 5.6 versions earlier than 5.6.30Oracle MySQL Server 5.7 versions earlier than 5.7.12

10 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.1 High

AI Score

Confidence

Low

0.953 High

EPSS

Percentile

99.4%