-
Notifications
You must be signed in to change notification settings - Fork 0
CVE-2017-3523 @ Maven-mysql:mysql-connector-java-5.1.26 #55
Description
Vulnerable Package issue exists @ Maven-mysql:mysql-connector-java-5.1.26 in branch master
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Namespace: TaynaCT
Repository: JavaVulnerableLab
Repository Url: https://github.com/TaynaCT/JavaVulnerableLab
CxAST-Project: TaynaCT/JavaVulnerableLab
CxAST platform scan: 8306ce52-f0ea-4229-8014-fe5126ba5a64
Branch: master
Application: JavaVulnerableLab
Severity: HIGH
State: NOT_IGNORED
Status: RECURRENT
CWE: CWE-284
Addition Info
Attack vector: NETWORK
Attack complexity: HIGH
Confidentiality impact: HIGH
Availability impact: HIGH