CVE-2017-3589: Low severity Oracle Connector\/j vulnerability
An unspecified vulnerability in Oracle MySQL related to the Connectors Connector/J component could allow an authenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
Other sources
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data. CVSS 3.0 Base Score 3.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle MySQL (MySQL Connectors: Connector/J)to a version that resolves this vulnerability.Fixed in 5.1.41
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3589?
CVE-2017-3589 is considered an easily exploitable vulnerability, allowing a low privileged attacker to compromise the affected system.
How do I fix CVE-2017-3589?
To fix CVE-2017-3589, upgrade the Oracle MySQL Connector/J to a version later than 5.1.41.
Which versions of Oracle MySQL are affected by CVE-2017-3589?
Oracle MySQL Connector/J versions 5.1.41 and earlier are affected by CVE-2017-3589.
Who can exploit CVE-2017-3589?
CVE-2017-3589 can be exploited by low privileged attackers who have logon access to the infrastructure where MySQL Connectors executes.
What component does CVE-2017-3589 affect?
CVE-2017-3589 affects the MySQL Connectors component of Oracle MySQL, specifically the Connector/J subcomponent.