CVE-2015-4737: Low severity oracle solaris and zettabyte file system (zfs) vulnerability
Published Jul 16, 2015
·Updated
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier, and 5.6.23 and earlier, allows remote authenticated users to affect confidentiality via unknown vectors related to Server : Pluggable Auth.
Affected Software
8 affected components
Oracle Solaris=11.3
Oracle MySQL>=5.5.0<=5.5.43
Oracle MySQL>=5.6.0<=5.6.24
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=14.10
Canonical Ubuntu Linux=15.04
Debian Debian Linux=8.0
Remediation
Event History
Jul 16, 2015
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4737?
CVE-2015-4737 is classified as a moderate severity vulnerability due to its potential impact on the confidentiality of Oracle MySQL Server.
2
What versions of MySQL are affected by CVE-2015-4737?
CVE-2015-4737 affects MySQL Server versions 5.5.43 and earlier, and 5.6.23 and earlier.
3
How do I fix CVE-2015-4737?
To fix CVE-2015-4737, upgrade your MySQL Server to a version that is higher than 5.5.43 or 5.6.23.
4
Who can exploit CVE-2015-4737?
CVE-2015-4737 can be exploited by remote authenticated users who have access to the affected MySQL server.
5
What are the potential impacts of CVE-2015-4737?
Exploitation of CVE-2015-4737 may affect the confidentiality of data managed by the Oracle MySQL Server.