CVE-2017-3523
high
CVSS v3
8.5
CVSS v2
6.0
VIR risk
8.5
Description
Improper Access Control in MySQL Connectors Java
Predictions
Exploit likelihood
90%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-3523.html
Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | mysql:mysql-connector-java | <5.1.41 | 5.1.41 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| oracle | connector\/j | {"endIncluding":"5.1.40"} | |
References
Verify integrity in audit chain (admin only). AS-IS.