Vulnerability in MySQL Enterprise Monitor from Oracle MySQL
CVE-2017-3306

8.3HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability exists in the MySQL Enterprise Monitor component of Oracle MySQL that can be exploited by a high-privileged attacker with network access using various protocols. The attacker requires human interaction from a third party to successfully execute the attack. While this vulnerability primarily affects MySQL Enterprise Monitor, it can also lead to significant impacts on other connected products. Exploitation may allow unauthorized creation, deletion, or modification of data, including critical MySQL Enterprise Monitor accessible data, and even a partial denial of service. This emphasizes the need for vigilant security measures to safeguard sensitive information.

Affected Version(s)

MySQL Enterprise Monitor 3.1.6.8003 and earlier

MySQL Enterprise Monitor 3.2.1182 and earlier

MySQL Enterprise Monitor 3.3.2.1162 and earlier

References

CVSS V3.1

Score:
8.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.