Junglewise Threat Intelligence

CVE-2016-5590: Oracle MySQL Enterprise Monitor takeover in Monitoring Agent

CVE-2016-5590 · Severity: high · CVSS 7.2 · Published 2017-01-27

Vendors: Oracle.

Executive brief

A vulnerability in the MySQL Enterprise Monitor agent allows a high-privileged user to take full control of the monitoring system. MySQL Enterprise Monitor is used by organizations to track the health and performance of their database infrastructure. A successful exploit could lead to a complete compromise of the monitoring platform, potentially exposing sensitive database performance data or disrupting administrative operations.

Technical details

A vulnerability in the Monitoring: Agent subcomponent of Oracle MySQL Enterprise Monitor (versions 3.1.3.7856 and earlier) allows for a complete system takeover. The flaw is easily exploitable by a high-privileged attacker with network access via TLS. While specific technical details regarding the root cause (such as the specific CWE) are not disclosed in the advisory, the exploit results in high impacts to confidentiality, integrity, and availability. Oracle addressed this issue in the January 2017 Critical Patch Update.

Affected products

  • Oracle MySQL Enterprise Monitor 3.1.3.7856 and earlier

Timeline

  • 2017-01-27: disclosed: Initial disclosure by Oracle
  • 2017-01-27: advisory: NVD publication date

References