Vulnerability in MySQL Enterprise Monitor Component
CVE-2017-10424

8.8HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 October 2017

Summary

A significant vulnerability exists in the MySQL Enterprise Monitor component of Oracle MySQL that allows an unauthenticated attacker to exploit the system through various network protocols. The attacker requires human interaction from a user other than themselves to successfully execute the attack. This situation may lead to a full compromise of the MySQL Enterprise Monitor, which can have severe implications for the confidentiality, integrity, and availability of monitored data.

Affected Version(s)

MySQL Enterprise Monitor 3.2.8.2223 and earlier

MySQL Enterprise Monitor 3.3.4.3247 and earlier

MySQL Enterprise Monitor 3.4.2.4181 and earlier

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.