CVE-2017-10277

EUVD-2017-1924
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 75%
Affected Products (NVD)
VendorProductVersion
oraclemysql_connector\/net
𝑥
≤ 6.9.9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mariadb-10.0
artful
dne
trusty
dne
xenial
not-affected
zesty
dne
mariadb-10.1
artful
not-affected
trusty
dne
xenial
dne
zesty
not-affected
mariadb-5.5
artful
dne
trusty
dne
xenial
dne
zesty
dne
mysql-5.5
artful
dne
trusty
not-affected
vivid
dne
xenial
dne
zesty
dne
mysql-5.6
artful
dne
trusty
dne
xenial
dne
zesty
dne
mysql-5.7
artful
not-affected
trusty
dne
xenial
not-affected
zesty
not-affected
percona-server-5.6
artful
not-affected
trusty
dne
xenial
not-affected
zesty
not-affected
percona-xtradb-cluster-5.5
artful
dne
trusty
dne
xenial
dne
zesty
dne
percona-xtradb-cluster-5.6
artful
not-affected
trusty
dne
xenial
not-affected
zesty
not-affected