[Forgot Password]
Login  Register Subscribe

30389

 
 

423868

 
 

244411

 
 

909

 
 

193363

 
 

277

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2018-2755Date: (C)2018-04-24   (M)2024-02-01


Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.59 and prior, 5.6.39 and prior and 5.7.21 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.0 Base Score 7.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 7.7CVSS Score : 3.7
Exploit Score: 1.0Exploit Score: 1.9
Impact Score: 6.0Impact Score: 6.4
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: HIGHAccess Complexity: HIGH
Privileges Required: NONEAuthentication: NONE
User Interaction: REQUIREDConfidentiality: PARTIAL
Scope: CHANGEDIntegrity: PARTIAL
Confidentiality: HIGHAvailability: PARTIAL
Integrity: HIGH 
Availability: HIGH 
  
Reference:
BID-103807
SECTRACK-1040698
DSA-4176
DSA-4341
GLSA-201908-24
RHSA-2018:1254
RHSA-2018:2439
RHSA-2018:2729
RHSA-2018:3655
RHSA-2019:1258
USN-3629-1
USN-3629-2
USN-3629-3
https://lists.debian.org/debian-lts-announce/2018/04/msg00020.html
https://lists.debian.org/debian-lts-announce/2018/06/msg00015.html
http://www.oracle.com/technetwork/security-advisory/cpuapr2018-3678067.html
https://security.netapp.com/advisory/ntap-20180419-0002/

CPE    9
cpe:/o:debian:debian_linux:9.0
cpe:/o:debian:debian_linux:7.0
cpe:/a:mariadb:mariadb
cpe:/o:redhat:enterprise_linux_workstation:7.0
...
OVAL    37
oval:org.secpod.oval:def:1600889
oval:org.secpod.oval:def:1600887
oval:org.secpod.oval:def:89043761
oval:org.secpod.oval:def:2101813
...

© SecPod Technologies