Executive brief
A vulnerability exists in the X Plugin component of Oracle MySQL Server, a widely used database system. A low-privileged attacker with network access could exploit this flaw to gain unauthorized read access to a portion of the data stored on the server. While the vulnerability is difficult to exploit, it could lead to the exposure of sensitive business information.
Technical details
A vulnerability in the Server: X Plugin subcomponent of Oracle MySQL Server (versions 5.7.16 and earlier) allows an authenticated, low-privileged attacker with network access via multiple protocols to compromise the server. The vulnerability is characterized by high attack complexity, requiring specific conditions to be met for successful exploitation. If exploited, the attacker can achieve unauthorized read access to a subset of MySQL Server accessible data (CWE-200). Oracle addressed this in the January 2017 Critical Patch Update, and users are advised to upgrade to MySQL 5.7.17 or later.
Affected products
- Oracle MySQL Server 5.7.16 and earlier
Timeline
- 2017-01-27: advisory: Initial NVD publication
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released