CVE-2015-0433: Medium severity oracle communications policy management vulnerability
Published Apr 16, 2015
·Updated
Unspecified vulnerability in Oracle MySQL Server 5.5.41 and earlier, and 5.6.22 and earlier, allows remote authenticated users to affect availability via vectors related to InnoDB : DML.
Affected Software
38 affected components
Oracle Communications Policy Management<=9.7.3
Oracle Communications Policy Management=9.9.1
Oracle Communications Policy Management=10.4.1
Oracle Communications Policy Management=12.1.1
Oracle MySQL>=5.5.0<=5.5.41
Oracle MySQL>=5.6.0<=5.6.22
Oracle Solaris=11.3
Debian Debian Linux=7.0
Debian Debian Linux=8.0
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Eus=7.1
redhat Enterprise Linux Eus=7.2
redhat Enterprise Linux Eus=7.3
redhat Enterprise Linux Eus=7.4
redhat Enterprise Linux Eus=7.5
redhat Enterprise Linux Eus=7.6
redhat Enterprise Linux Eus=7.7
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=7.0
SUSE Linux Enterprise Desktop=11-sp3
SUSE Linux Enterprise Server=11-sp3
SUSE Linux Enterprise Server Vmware=11-sp3
SUSE Linux Enterprise Software Development Kit=11-sp3
MariaDB MariaDB>=5.5.0<5.5.42
MariaDB MariaDB>=10.0.0<10.0.17
Remediation
Event History
Apr 16, 2015
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-0433?
CVE-2015-0433 has been classified as a vulnerability that can affect the availability of the system.
2
How do I fix CVE-2015-0433?
To fix CVE-2015-0433, you should upgrade your Oracle MySQL Server to a version later than 5.5.41 or 5.6.22.
3
Which versions of MySQL are affected by CVE-2015-0433?
CVE-2015-0433 affects MySQL Server versions 5.5.41 and earlier, and 5.6.22 and earlier.
4
Can CVE-2015-0433 be exploited by unauthenticated users?
CVE-2015-0433 requires remote authenticated users for exploitation.
5
What vector types are associated with CVE-2015-0433?
The vectors related to CVE-2015-0433 are specifically tied to InnoDB and DML operations.