IT

Tracker / CVE-2018-3155

CVE-2018-3155

High 7.7

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Parser). Supported versions that are affected are 5.7.23 and prior and 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. While the vulnerability is in MySQL Server, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.0 Base Score 7.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H).

Affected products and versions

canonical ubuntu_linux
netapp oncommand_insight
netapp oncommand_unified_manager · 7.3 → …
netapp oncommand_unified_manager · 9.4 → …
netapp oncommand_workflow_automation
netapp snapcenter
netapp storage_automation_store
oracle mysql · 5.7.0 → 5.7.23
oracle mysql · 8.0.0 → 8.0.12

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References