CVE-2017-3322: Low severity ORACLE MySQL Cluster vulnerability
Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: NDBAPI). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier and . Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS v3.0 Base Score 3.7 (Availability impacts).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle MySQL Cluster (Cluster: NDBAPI)to a version that resolves this vulnerability.Fixed in 7.2.25 and earlier - Upgrade
Upgrade
Oracle MySQL Cluster (Cluster: NDBAPI)to a version that resolves this vulnerability.Fixed in 7.3.14 and earlier - Upgrade
Upgrade
Oracle MySQL Cluster (Cluster: NDBAPI)to a version that resolves this vulnerability.Fixed in 7.4.12 and earlier
Event History
Frequently Asked Questions
What is the severity of CVE-2017-3322?
CVE-2017-3322 is considered a difficult to exploit vulnerability that could allow an unauthenticated attacker with network access to affect the MySQL Cluster.
How do I fix CVE-2017-3322?
To fix CVE-2017-3322, upgrade to MySQL Cluster version 7.2.26 or later, 7.3.15 or later, or 7.4.13 or later.
What software versions are affected by CVE-2017-3322?
CVE-2017-3322 affects MySQL Cluster versions 7.2.25 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier.
What component of MySQL is affected by CVE-2017-3322?
CVE-2017-3322 affects the MySQL Cluster component within the Oracle MySQL software.
Can CVE-2017-3322 be exploited remotely?
Yes, CVE-2017-3322 can be exploited by an unauthenticated attacker with network access.