First published: Wed Jul 18 2018(Updated: )
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Core / Client). Supported versions that are affected are 8.0.11 and prior. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.0 Base Score 2.8 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | >=8.0.0<=8.0.11 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter | ||
NetApp Storage Automation Store |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3084 is considered an easily exploitable vulnerability affecting specific versions of MySQL Server, classified as a high-severity risk.
To fix CVE-2018-3084, upgrade your MySQL Server to version 8.0.12 or later.
CVE-2018-3084 affects MySQL Server versions 8.0.11 and earlier.
CVE-2018-3084 can be exploited by low privileged attackers who have logon access to the infrastructure where MySQL Server is running.
CVE-2018-3084 specifically impacts the core and client components of the MySQL Server.