Junglewise Threat Intelligence

CVE-2016-5541: Oracle MySQL Cluster unauthorized data modification in NDBAPI

CVE-2016-5541 · Severity: medium · CVSS 4.8 · Published 2017-01-27

Technologies: Oracle Mysql Cluster. Vendors: Oracle.

Executive brief

Oracle MySQL Cluster is a high-availability database technology used for mission-critical applications. A vulnerability in its NDBAPI component could allow an unauthenticated attacker to remotely modify or delete database records and cause partial service disruptions. While difficult to exploit, this flaw poses a risk to data integrity and the continuous availability of database services.

Technical details

This vulnerability exists in the NDBAPI subcomponent of Oracle MySQL Cluster (versions 7.2.26, 7.3.14, 7.4.12 and earlier). It is classified as a 'difficult to exploit' flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the cluster. Successful exploitation can result in unauthorized update, insert, or delete access to accessible data, as well as the ability to cause a partial denial of service (DoS). The vulnerability is tracked as CVE-2016-5541 and was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle MySQL Cluster 7.2.26 and earlier, 7.3.14 and earlier, 7.4.12 and earlier

Timeline

  • 2017-01-27: advisory: NVD publication date
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References

Related threats