Insufficient Security in MySQL Enterprise Monitor by Oracle
CVE-2017-3307

3.1LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
24 April 2017

Summary

A vulnerability exists in the MySQL Enterprise Monitor component of Oracle MySQL, specifically impacting certain versions. This issue allows an attacker with high privileges and network access to potentially compromise the MySQL Enterprise Monitor system, but requires human interaction from a third party. Successful exploits can lead to unauthorized changes to accessible data, including the ability to update, insert, or delete information, and could cause a partial denial of service.

Affected Version(s)

MySQL Enterprise Monitor 3.1.6.8003 and earlier

MySQL Enterprise Monitor 3.2.1182 and earlier

MySQL Enterprise Monitor 3.3.2.1162 and earlier

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.