CVE-2016-5598
published 2016-10-25CVE-2016-5598: Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect…
PriorityP432medium5.6CVSS 3.0
AVNACHPRNUINSUCLILAL
EPSS
2.21%
80.6th percentile
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | mysql-connector-python | < mysql-connector-python 2.1.5-1 (sid) | mysql-connector-python 2.1.5-1 (sid) |
| oracle | mysql_connector_python | 2.0.0 – 2.0.4 | — |
| oracle | mysql_connector_python | 2.1.0 – 2.1.3 | — |
CVSS provenance
nvdv3.05.6MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv5.6MEDIUM
vendor_debian5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2016-5598: mysql-connector-python - Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and...
vendor_debian·2016·CVSS 5.6
CVE-2016-5598 [MEDIUM] CVE-2016-5598: mysql-connector-python - Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and...
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.
Scope: local
sid: resolved (fixed in 2.1.5-1)
GHSA
GHSA-j5cf-mr37-wmwc: Unspecified vulnerability in the MySQL Connector component 2
ghsa_unreviewed·2022-05-14
CVE-2016-5598 [MEDIUM] CWE-284 GHSA-j5cf-mr37-wmwc: Unspecified vulnerability in the MySQL Connector component 2
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.
OSV
CVE-2016-5598: Unspecified vulnerability in the MySQL Connector component 2
osv·2016-10-25·CVSS 5.6
CVE-2016-5598 [MEDIUM] CVE-2016-5598: Unspecified vulnerability in the MySQL Connector component 2
Unspecified vulnerability in the MySQL Connector component 2.1.3 and earlier and 2.0.4 and earlier in Oracle MySQL allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Connector/Python.
No detection rules found.
No public exploits indexed.
Qualys
Oracle October 2016 Critical Patch Update | Qualys
blogs_qualys·2016-10-19·CVSS 6.1
[MEDIUM] Oracle October 2016 Critical Patch Update | Qualys
Oracle released another massive patch update today which fixed 253 security flaws across hundreds of Oracle products. This year we have seen the updates getting bigger as compared to an average of 161 vulnerabilities 2015 and 128 vulnerabilities in 2014. Many components fixed in today’s release are remotely exploitable. Since most organizations have different teams to patch databases, networking components, operating systems, applications server and ERP systems, I have broken down the massive update in these categories. Other than the exception of Java there are no consumer products and administrators should focus on their individual patching domains.
On the database front there were 31 vulnerabilities fixed in MySQL as compared to 12 in the Oracle database. Databases are typically not ex
Qualys
Oracle October 2016 Critical Patch Update | Qualys
blogs_qualys·2016-10-18·CVSS 6.1
[MEDIUM] Oracle October 2016 Critical Patch Update | Qualys
Oracle released another massive patch update today which fixed 253 security flaws across hundreds of Oracle products. This year we have seen the updates getting bigger as compared to an average of 161 vulnerabilities 2015 and 128 vulnerabilities in 2014. Many components fixed in today’s release are remotely exploitable. Since most organizations have different teams to patch databases, networking components, operating systems, applications server and ERP systems, I have broken down the massive update in these categories. Other than the exception of Java there are no consumer products and administrators should focus on their individual patching domains.
On the database front there were 31 vulnerabilities fixed in MySQL as compared to 12 in the Oracle database. Databases are typically not ex
Bugzilla
CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python [epel-all]
bugzilla·2016-10-19·CVSS 5.6
CVE-2016-5598 [MEDIUM] CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python [epel-all]
CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python [epel-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora EPEL.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue aff
Bugzilla
CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python
bugzilla·2016-10-19·CVSS 5.6
CVE-2016-5598 [MEDIUM] CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python
CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python
Vulnerability in the MySQL Connector component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.3 and earlier and 2.0.4 and earlier. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connector. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connector accessible data as well as unauthorized read access to a subset of MySQL Connector accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connector.
External References:
http://www.oracle.com/technetwork/se
Bugzilla
CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python [fedora-all]
bugzilla·2016-10-19·CVSS 5.6
CVE-2016-5598 [MEDIUM] CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python [fedora-all]
CVE-2016-5598 mysql-connector-python: Unspecified vulnerability in subcomponent: Connector/Python [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affect
http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93653http://www.securitytracker.com/id/1037050http://www.oracle.com/technetwork/security-advisory/cpuoct2016-2881722.htmlhttp://www.securityfocus.com/bid/93653http://www.securitytracker.com/id/1037050
2016-10-25
Published