CVE-2017-3586

Severity
6.4MEDIUM
EPSS
0.8%
top 25.91%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 24
Latest updateMay 13

Description

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:NExploitability: 3.1 | Impact: 2.7

Affected Packages3 packages

CVEListV5oracle_corporation/mysql_connectors5.1.41 and earlier

Patches

🔴Vulnerability Details

4
GHSA
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java2022-05-13
OSV
Exposure of Sensitive Information to an Unauthorized Actor in Oracle MySQL Connectors Java2022-05-13
OSV
CVE-2017-3586: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J)2017-04-24
CVEList
CVE-2017-3586: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J)2017-04-24

📋Vendor Advisories

1
Red Hat
mysql-connector-java: Connector/J unspecified vulnerability (CPU Apr 2017)2017-04-19

💬Community

2
Bugzilla
CVE-2017-3523 CVE-2017-3586 CVE-2017-3589 mysql-connector-java: various flaws [fedora-all]2017-04-21
Bugzilla
CVE-2017-3586 mysql-connector-java: Connector/J unspecified vulnerability (CPU Apr 2017)2017-04-21
CVE-2017-3586 (MEDIUM CVSS 6.4) | Vulnerability in the MySQL Connecto | cvebase.io