CVE-2017-3523: High severity Oracle Connector\/j vulnerability
An unspecified vulnerability in Oracle MySQL related to the Connectors Connector/J component could allow an authenticated attacker to cause high confidentiality impact, high integrity impact, and high availability impact.
Other sources
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle MySQL (MySQL Connectors - Connector/J)to a version that resolves this vulnerability.Fixed in 5.1.40
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3523?
The severity of CVE-2017-3523 is classified as high for confidentiality, integrity, and availability impacts.
How do I fix CVE-2017-3523?
To fix CVE-2017-3523, ensure you upgrade to a version of Oracle Connector/J newer than 5.1.40.
Who is affected by CVE-2017-3523?
CVE-2017-3523 affects users of Oracle Connector/J and specific IBM products including Data Virtualization and Watson Query on Cloud Pak for Data.
What type of vulnerability is CVE-2017-3523?
CVE-2017-3523 is an unspecified vulnerability that may allow authenticated attackers to compromise confidentiality, integrity, and availability.
Is authentication required to exploit CVE-2017-3523?
Yes, exploitation of CVE-2017-3523 requires the attacker to be authenticated.