REDHAT-BUG-1640615: High severity Oracle MySQL Connectors vulnerability
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors.
References:
http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2018-3258 http://www.oracle.com/technetwork/security-advisory/cpuoct2018-4428296.html#CVE-2018-3258
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Oracle MySQL Connector/J (MySQL Connectors)to a version that resolves this vulnerability.Fixed in 8.0.12 and prior
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-1640615?
REDHAT-BUG-1640615 is classified as an easily exploitable vulnerability that allows attackers with low privileges to compromise MySQL Connectors.
How do I fix REDHAT-BUG-1640615?
To mitigate the REDHAT-BUG-1640615 vulnerability, upgrade to MySQL Connectors version 8.0.13 or later.
Who is affected by REDHAT-BUG-1640615?
The vulnerability REDHAT-BUG-1640615 affects all supported versions of Oracle MySQL Connectors up to 8.0.12.
What impact does REDHAT-BUG-1640615 have on MySQL Connectors?
The impact of REDHAT-BUG-1640615 allows an unauthorized attacker to compromise MySQL Connectors through network access.
Can REDHAT-BUG-1640615 be exploited remotely?
Yes, the vulnerability REDHAT-BUG-1640615 can be exploited remotely as it allows network access via multiple protocols.