CVE-2015-4864: Low severity oracle solaris and zettabyte file system (zfs) vulnerability
Published Oct 21, 2015
·Updated
Unspecified vulnerability in Oracle MySQL Server 5.5.43 and earlier and 5.6.24 and earlier allows remote authenticated users to affect integrity via unknown vectors related to Server : Security : Privileges.
Affected Software
30 affected components
Oracle Solaris=11.3
Oracle MySQL>=5.5.0<=5.5.43
Oracle MySQL>=5.6.0<=5.6.24
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=14.04
Canonical Ubuntu Linux=15.04
Canonical Ubuntu Linux=15.10
redhat Enterprise Linux Desktop=5.0
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Eus=7.1
redhat Enterprise Linux Eus=7.2
redhat Enterprise Linux Eus=7.3
redhat Enterprise Linux Eus=7.4
redhat Enterprise Linux Eus=7.5
redhat Enterprise Linux Eus=7.6
redhat Enterprise Linux Eus=7.7
redhat Enterprise Linux Server=5.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Server Aus=7.3
redhat Enterprise Linux Server Aus=7.4
redhat Enterprise Linux Server Aus=7.6
redhat Enterprise Linux Server Aus=7.7
redhat Enterprise Linux Server Tus=7.3
redhat Enterprise Linux Server Tus=7.6
redhat Enterprise Linux Server Tus=7.7
redhat Enterprise Linux Workstation=5.0
redhat Enterprise Linux Workstation=7.0
MariaDB MariaDB>=5.5.0<5.5.44
MariaDB MariaDB>=10.0.0<10.0.20
MariaDB MariaDB>=10.1.0<10.1.8
Remediation
Event History
Oct 21, 2015
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2015-4864?
CVE-2015-4864 is considered a low to medium severity vulnerability affecting Oracle MySQL Server.
2
How do I fix CVE-2015-4864?
To fix CVE-2015-4864, update your Oracle MySQL Server to a version later than 5.5.43 or 5.6.24.
3
Who is affected by CVE-2015-4864?
CVE-2015-4864 affects remote authenticated users of Oracle MySQL Server versions 5.5.43 and earlier and 5.6.24 and earlier.
4
What kind of attacks can exploit CVE-2015-4864?
CVE-2015-4864 can be exploited by remote authenticated users to affect data integrity through unspecified vectors.
5
Is there a workaround for CVE-2015-4864?
There are no specific workarounds for CVE-2015-4864, so upgrading to the latest version is recommended.