CVE-2017-3304: Medium severity ORACLE MySQL Cluster vulnerability
Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: DD). Supported versions that are affected are 7.2.27 and earlier, 7.3.16 and earlier, 7.4.14 and earlier and 7.5.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Cluster accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS 3.0 Base Score 5.4 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3304?
CVE-2017-3304 has been classified as a high-severity vulnerability due to its easy exploitability and potential impact on affected systems.
How do I fix CVE-2017-3304?
To fix CVE-2017-3304, upgrade your MySQL Cluster installation to version 7.2.28 or later, version 7.3.17 or later, version 7.4.15 or later, or version 7.5.6 or later.
Which MySQL Cluster versions are affected by CVE-2017-3304?
CVE-2017-3304 affects MySQL Cluster versions 7.2.27 and earlier, 7.3.16 and earlier, 7.4.14 and earlier, and 7.5.5 and earlier.
Who can exploit CVE-2017-3304?
CVE-2017-3304 can be exploited by low privileged attackers with network access, making it a significant risk for exposed services.
What component of MySQL is affected by CVE-2017-3304?
CVE-2017-3304 affects the MySQL Cluster component specifically under the subcomponent 'Cluster: DD'.