Oracle Mysql Enterprise Monitor vulnerabilities
58 known vulnerabilities affecting oracle/mysql_enterprise_monitor.
Total CVEs
58
CISA KEV
7
actively exploited
Public exploits
11
Exploited in wild
7
Severity breakdown
CRITICAL12HIGH30MEDIUM15LOW1
Vulnerabilities
Page 3 of 3
CVE-2019-17571CRITICALCVSS 9.8≤ 8.0.292019-12-20
CVE-2019-17571 [CRITICAL] CWE-502 CVE-2019-17571: Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted dat
Included in Log4j 1.2 is a SocketServer class that is vulnerable to deserialization of untrusted data which can be exploited to remotely execute arbitrary code when combined with a deserialization gadget when listening to untrusted network traffic for log data. This affects Log4j versions up to 1.2 up to 1.2.17.
nvd
CVE-2019-1551MEDIUMCVSS 5.3≤ 4.0.12≥ 8.0.0, ≤ 8.0.202019-12-06
CVE-2019-1551 [MEDIUM] CWE-190 CVE-2019-1551: There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512
There is an overflow bug in the x64_64 Montgomery squaring procedure used in exponentiation with 512-bit moduli. No EC algorithms are affected. Analysis suggests that attacks against 2-prime RSA1024, 3-prime RSA1536, and DSA1024 as a result of this defect would be very difficult to perform and are not believed likely. Attacks against DH512 are conside
nvd
CVE-2019-1559MEDIUMCVSS 5.9≤ 4.0.8≥ 8.0.0, ≤ 8.0.142019-02-27
CVE-2019-1559 [MEDIUM] CWE-203 CVE-2019-1559: If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to sen
If an application encounters a fatal protocol error and then calls SSL_shutdown() twice (once to send a close_notify, and once to receive one) then OpenSSL can respond differently to the calling application if a 0 byte record is received with invalid padding compared to if a 0 byte record is received with an invalid MAC. If the application then behave
nvd
CVE-2018-15756HIGHCVSS 7.5≤ 4.0.12≥ 8.0.0, ≤ 8.0.202018-10-18
CVE-2018-15756 [HIGH] CVE-2018-15756: Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and o
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving static resources through the ResourceHttpRequestHandler, or starting in 5.0 when an annotated controller returns an org.springframework.core.io.Resource. A malicious u
nvd
CVE-2018-11776HIGHCVSS 8.1KEVPoC≤ 3.4.9.4237≥ 4.0.0, ≤ 4.0.6.5281+1 more2018-08-22
CVE-2018-11776 [HIGH] CVE-2018-11776: Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution wh
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true (either by user or a plugin like Convention Plugin) and then: results are used with no namespace and in same time, its upper package have no or wildcard namespace and similar to results, same possibility when using url tag w
nvd
CVE-2018-11040HIGHCVSS 7.5≤ 3.4.9.4237≥ 3.4.10, ≤ 4.0.6.5281+1 more2018-06-25
CVE-2018-11040 [HIGH] CWE-829 CVE-2018-11040: Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported vers
Spring Framework, versions 5.0.x prior to 5.0.7 and 4.3.x prior to 4.3.18 and older unsupported versions, allows web applications to enable cross-domain requests via JSONP (JSON with Padding) through AbstractJsonpResponseBodyAdvice for REST controllers and MappingJackson2JsonView for browser requests. Both are not enabled by default in Spring Framewor
nvd
CVE-2018-11039MEDIUMCVSS 5.9≤ 3.4.9.4237≥ 4.0.0, ≤ 4.0.6.5281+1 more2018-06-25
CVE-2018-11039 [MEDIUM] CVE-2018-11039: Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupport
Spring Framework (versions 5.0.x prior to 5.0.7, versions 4.3.x prior to 4.3.18, and older unsupported versions) allow web applications to change the HTTP request method to any HTTP method (including TRACE) using the HiddenHttpMethodFilter in Spring MVC. If an application has a pre-existing XSS vulnerability, a malicious user (or attacker) can use this filt
nvd
CVE-2018-1258HIGHCVSS 8.8≤ 8.0.2.81912018-05-11
CVE-2018-1258 [HIGH] CWE-863 CVE-2018-1258: Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contain
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
nvd
CVE-2017-10424HIGHCVSS 8.8v3.2.0v3.2.1+18 more2017-10-19
CVE-2017-10424 [HIGH] CVE-2017-10424: Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: W
Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Web). Supported versions that are affected are 3.2.8.2223 and earlier, 3.3.4.3247 and earlier and 3.4.2.4181 and earlier. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Enterprise M
nvd
CVE-2017-12617HIGHCVSS 8.1KEVPoC≤ 3.3.6.3293≥ 3.4.0, ≤ 3.4.4.4226+1 more2017-10-04
CVE-2017-12617 [HIGH] CWE-434 CVE-2017-12617: When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.
When running Apache Tomcat versions 9.0.0.M1 to 9.0.0, 8.5.0 to 8.5.22, 8.0.0.RC1 to 8.0.46 and 7.0.0 to 7.0.81 with HTTP PUTs enabled (e.g. via setting the readonly initialisation parameter of the Default servlet to false) it was possible to upload a JSP file to the server via a specially crafted request. This JSP could then be requested and any code
nvd
CVE-2017-3306HIGHCVSS 8.3≥ 3.1.0, ≤ 3.1.6.8003≥ 3.2.0, ≤ 3.2.1182+1 more2017-04-24
CVE-2017-3306 [HIGH] CVE-2017-3306: Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: S
Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Server). Supported versions that are affected are 3.1.6.8003 and earlier, 3.2.1182 and earlier and 3.3.2.1162 and earlier. Easily "exploitable" vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise
nvd
CVE-2017-3307LOWCVSS 3.1≥ 3.1.0, ≤ 3.1.6.8003≥ 3.2.0, ≤ 3.2.1182+1 more2017-04-24
CVE-2017-3307 [LOW] CVE-2017-3307: Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: S
Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Server). Supported versions that are affected are 3.1.6.8003 and earlier, 3.2.1182 and earlier and 3.3.2.1162 and earlier. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Enterprise M
nvd
CVE-2017-5645CRITICALCVSS 9.8PoC≥ 3.4.0.0, ≤ 3.4.7.4297≥ 4.0.0.0, ≤ 4.0.4.5235+1 more2017-04-17
CVE-2017-5645 [CRITICAL] CWE-502 CVE-2017-5645: In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive s
In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code.
nvd
CVE-2016-8735CRITICALCVSS 9.8KEVPoC≤ 3.2.8.2223≥ 3.3.0, ≤ 3.3.4.3247+1 more2017-04-06
CVE-2016-8735 [CRITICAL] CVE-2016-8735: Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.
Remote code execution is possible with Apache Tomcat before 6.0.48, 7.x before 7.0.73, 8.x before 8.0.39, 8.5.x before 8.5.7, and 9.x before 9.0.0.M12 if JmxRemoteLifecycleListener is used and an attacker can reach JMX ports. The issue exists because this listener wasn't updated for consistency with the CVE-2016-3427 Oracle patch that affected credential ty
nvd
CVE-2016-5590HIGHCVSS 7.2≤ 3.1.3.7856v3.1.3.7856 and earlier2017-01-27
CVE-2016-5590 [HIGH] CVE-2016-5590: Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: A
Vulnerability in the MySQL Enterprise Monitor component of Oracle MySQL (subcomponent: Monitoring: Agent). Supported versions that are affected are 3.1.3.7856 and earlier. Easily exploitable vulnerability allows high privileged attacker with network access via TLS to compromise MySQL Enterprise Monitor. Successful attacks of this vulnerability can result in tak
cvelistv5nvd
CVE-2016-3461HIGHCVSS 7.2v3.0.25v3.1.22016-04-21
CVE-2016-3461 [HIGH] CVE-2016-3461: Unspecified vulnerability in the MySQL Enterprise Monitor component in Oracle MySQL 3.0.25 and earli
Unspecified vulnerability in the MySQL Enterprise Monitor component in Oracle MySQL 3.0.25 and earlier and 3.1.2 and earlier allows remote administrators to affect confidentiality, integrity, and availability via vectors related to Monitoring: Server.
nvd
CVE-2015-3144CRITICALCVSS 9.0≤ 2.3.20≤ 3.0.222015-04-24
CVE-2015-3144 [CRITICAL] CWE-119 CVE-2015-3144: The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an i
The fix_hostname function in cURL and libcurl 7.37.0 through 7.41.0 does not properly calculate an index, which allows remote attackers to cause a denial of service (out-of-bounds read or write and crash) or possibly have other unspecified impact via a zero-length host name, as demonstrated by "http://:80" and ":80."
nvd
CVE-2013-4316CRITICALCVSS 10.0≤ 2.3.14≤ 3.0.42013-09-30
CVE-2013-4316 [CRITICAL] CWE-16 CVE-2013-4316: Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.
nvd
← Previous3 / 3