CVE-2017-3589
low
CVSS v3
3.3
CVSS v2
2.1
VIR risk
3.3
Description
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java
Predictions
Exploit likelihood
34%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2017-3589.html
Vendor advisory: secalert_us@oracle.com — http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.html
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| sles | affected | |
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | mysql:mysql-connector-java | <5.1.42 | 5.1.42 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| oracle | connector\/j | {"endIncluding":"5.1.41"} | |
References
Verify integrity in audit chain (admin only). AS-IS.