Lucene search

K
nessusTenable700062.PRM
HistoryApr 20, 2017 - 12:00 a.m.

Oracle MySQL 5.5.x < 5.5.55 Multiple Vulnerabilities

2017-04-2000:00:00
Tenable
www.tenable.com
26

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

7.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

71.3%

The version of MySQL installed on the remote host is version 5.5.x prior to 5.5.55 and is affected by multiple issues :

  • An unspecified flaw exists related to the DML subcomponent. This may allow an authenticated remote attacker to cause a denial of service. No further details have been provided by the vendor. (CVE-2017-3308, CVE-2017-3456)
  • An unspecified flaw exists related to the Optimizer subcomponent. This may allow an authenticated remote attacker to cause a denial of service. No further details have been provided by the vendor. (CVE-2017-3309, CVE-2017-3452, CVE-2017-3453)
  • An unspecified flaw exists related to the Thread Pooling subcomponent. This may allow a remote attacker to cause a denial of service. No further details have been provided by the vendor. (CVE-2017-3329)
  • An unspecified flaw exists related to the Security: Privileges subcomponent. This may allow an authenticated attacker to cause a denial of service. No further details have been provided by the vendor. (CVE-2017-3461, CVE-2017-3462, CVE-2017-3463)
  • An unspecified flaw exists related to the DDL subcomponent. This may allow an authenticated attacker to have an impact on integrity. No further details have been provided by the vendor. (CVE-2017-3464)
  • An unspecified flaw exists related to the Client mysqldump subcomponent. This may allow an authenticated attacker to potentially execute arbitrary code. No further details have been provided by the vendor. (CVE-2017-3600)
Binary data 700062.prm
VendorProductVersionCPE
oraclemysqlcpe:/a:oracle:mysql

6 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:S/C:P/I:P/A:P

7.7 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

0.003 Low

EPSS

Percentile

71.3%