First published: Mon Apr 24 2017(Updated: )
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 2.1.5 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data. CVSS 3.0 Base Score 3.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Connector\/python | <=2.1.5 | |
pip/mysql-connector-python | <=2.1.5 | |
<=2.1.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-3590 is considered an easily exploitable vulnerability.
To fix CVE-2017-3590, upgrade MySQL Connector/Python to version 2.1.6 or later.
CVE-2017-3590 affects MySQL Connector/Python versions 2.1.5 and earlier.
CVE-2017-3590 can be exploited by low privileged attackers with logon access to the infrastructure where MySQL Connectors execute.
CVE-2017-3590 impacts the MySQL Connectors component of Oracle MySQL, specifically the Connector/Python subcomponent.