Junglewise Threat Intelligence

CVE-2017-3320: Oracle MySQL Server information disclosure in Encryption subcomponent

CVE-2017-3320 · Severity: low · CVSS 2.4 · Published 2017-01-27

Technologies: Oracle Mysql, Oracle MySQL Server. Vendors: Oracle.

Executive brief

A vulnerability exists in the encryption subcomponent of Oracle MySQL Server, a widely used database system. A highly privileged attacker could exploit this flaw to gain unauthorized read access to a specific subset of data. Successful exploitation requires interaction from a person other than the attacker, such as an administrator performing a specific action.

Technical details

A vulnerability in the Server: Security: Encryption subcomponent of Oracle MySQL Server (specifically version 5.7.16 and earlier) allows a high-privileged attacker with network access via multiple protocols to compromise the server. The vulnerability is classified as 'unspecified' by the vendor but is noted to impact confidentiality. Exploitation is considered easy but requires human interaction from a user other than the attacker (UI:R). Successful attacks result in unauthorized read access to a subset of MySQL Server accessible data. The issue was addressed in the Oracle Critical Patch Update for January 2017.

Affected products

  • Oracle MySQL Server 5.7.16 and earlier

Timeline

  • 2017-01-27: advisory: Initial NVD publication
  • 2017-01-17: patched: Oracle January 2017 Critical Patch Update released

References

Related threats