CVE-2017-10277

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Net). Supported versions that are affected are 6.9.9 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.0 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N).
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.4 MEDIUM
NETWORK
LOW
NONE
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
oracleCNA
---
---
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 74%
VendorProductVersion
oraclemysql_connector\/net
𝑥
≤ 6.9.9
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
mariadb-10.0
artful
dne
zesty
dne
xenial
not-affected
trusty
dne
mariadb-10.1
artful
not-affected
zesty
not-affected
xenial
dne
trusty
dne
mariadb-5.5
artful
dne
zesty
dne
xenial
dne
trusty
dne
mysql-5.5
artful
dne
zesty
dne
xenial
dne
vivid
dne
trusty
not-affected
mysql-5.6
artful
dne
zesty
dne
xenial
dne
trusty
dne
mysql-5.7
artful
not-affected
zesty
not-affected
xenial
not-affected
trusty
dne
percona-server-5.6
artful
not-affected
zesty
not-affected
xenial
not-affected
trusty
dne
percona-xtradb-cluster-5.5
artful
dne
zesty
dne
xenial
dne
trusty
dne
percona-xtradb-cluster-5.6
artful
not-affected
zesty
not-affected
xenial
not-affected
trusty
dne