Vulnerability Name:

CVE-2015-2575 (CCN-102348)

Assigned:2015-04-14
Published:2015-04-14
Updated:2017-11-10
Summary:Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.
CVSS v3 Severity:3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): Low
User Interaction (UI): Required
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N)
3.6 Low (Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
4.9 Medium (CCN CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N)
3.6 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:S/C:P/I:P/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Other
References:Source: MITRE
Type: CNA
CVE-2015-2575

Source: SUSE
Type: Third Party Advisory
SUSE-SU-2015:0946

Source: SUSE
Type: Broken Link
openSUSE-SU-2015:0967

Source: DEBIAN
Type: Third Party Advisory
DSA-3621

Source: CCN
Type: IBM Security Bulletin 2008901 (Security Guardium)
IBM Security Guardium is affected by Using Components with Known Vulnerabilities

Source: CCN
Type: Oracle Critical Patch Update - April 2015
Oracle Critical Patch Update - April 2015

Source: CONFIRM
Type: Vendor Advisory
http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html

Source: BID
Type: Third Party Advisory, VDB Entry
74075

Source: SECTRACK
Type: Third Party Advisory, VDB Entry
1032121

Source: XF
Type: UNKNOWN
oracle-cpuapr2015-cve20152575(102348)

Source: CONFIRM
Type: UNKNOWN
https://security.netapp.com/advisory/ntap-20150417-0003/

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2015-2575

Vulnerable Configuration:Configuration 1:
  • cpe:/o:debian:debian_linux:8.0:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/o:suse:linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
  • OR cpe:/o:opensuse:suse_linux_enterprise_server:11.0:sp3:*:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_server:11:sp3:vmware:*:*:*:*:*
  • OR cpe:/o:suse:linux_enterprise_software_development_kit:11:sp3:*:*:*:*:*:*

  • Configuration 3:
  • cpe:/a:mysql:mysql:*:*:*:*:*:*:*:* (Version <= 5.1.34)

  • Configuration CCN 1:
  • cpe:/a:oracle:mysql:5.1.34:-:*:*:*:*:*:*
  • AND
  • cpe:/a:ibm:security_guardium:10.0:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:10.0.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:10.1:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:10.1.2:*:*:*:*:*:*:*
  • OR cpe:/a:ibm:security_guardium:10.1.3:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:20152575
    V
    CVE-2015-2575
    2022-09-02
    oval:org.opensuse.security:def:113007
    P
    mysql-connector-java-5.1.35-2.3 on GA media (Moderate)
    2022-01-17
    oval:org.opensuse.security:def:10445
    P
    Security update for busybox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:10444
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:10436
    P
    Security update for libsndfile (Important)
    2022-01-11
    oval:org.opensuse.security:def:9892
    P
    Security update for go1.16 (Moderate)
    2021-12-23
    oval:org.opensuse.security:def:10432
    P
    Security update for p11-kit (Important)
    2021-12-22
    oval:org.opensuse.security:def:10381
    P
    Security update for fetchmail (Moderate)
    2021-12-14
    oval:org.opensuse.security:def:9623
    P
    Security update for mozilla-nss (Important)
    2021-12-06
    oval:org.opensuse.security:def:9825
    P
    Security update for clamav (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:10668
    P
    Security update for the Linux Kernel (Important)
    2021-12-06
    oval:org.opensuse.security:def:106453
    P
    Security update for samba (Important)
    2021-11-16
    oval:org.opensuse.security:def:10356
    P
    Security update for libvirt (Important)
    2021-10-27
    oval:org.opensuse.security:def:9601
    P
    Security update for python-Pygments (Important)
    2021-10-20
    oval:org.opensuse.security:def:10164
    P
    Security update for strongswan (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:9593
    P
    Security update for ffmpeg (Important)
    2021-09-23
    oval:org.opensuse.security:def:10154
    P
    Security update for ghostscript (Critical)
    2021-09-15
    oval:org.opensuse.security:def:10693
    P
    Security update for ntfs-3g_ntfsprogs (Important)
    2021-09-07
    oval:org.opensuse.security:def:10151
    P
    Security update for java-11-openjdk (Important)
    2021-09-03
    oval:org.opensuse.security:def:10142
    P
    Security update for openssl-1_0_0 (Important)
    2021-08-24
    oval:org.opensuse.security:def:10124
    P
    Security update for MozillaFirefox (Important)
    2021-07-27
    oval:org.opensuse.security:def:11105
    P
    Security update for icinga2 (Moderate)
    2021-07-21
    oval:org.opensuse.security:def:9731
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-06-17
    oval:org.opensuse.security:def:10281
    P
    Security update for squid (Important)
    2021-06-11
    oval:org.opensuse.security:def:10100
    P
    Security update for containerd, docker, runc (Important)
    2021-06-11
    oval:org.opensuse.security:def:11417
    P
    libyaml-0-2-0.1.6-1.19 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17014
    P
    libgio-fam-2.38.2-5.12 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16087
    P
    mysql-connector-java-5.1.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16653
    P
    shibboleth-sp-devel-2.5.5-6.3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17115
    P
    libFLAC++6-32bit-1.3.0-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16337
    P
    mysql-connector-java-5.1.35-3.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17046
    P
    dia-0.97.2-13.253 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:124625
    P
    mysql-connector-java-5.1.42-5.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16661
    P
    udisks2-devel-2.1.3-1.13 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:16619
    P
    mysql-connector-java-5.1.42-5.4.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17137
    P
    libvdpau1-32bit-1.1.1-6.73 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11395
    P
    libqt4-32bit-4.8.6-2.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:17103
    P
    gcc48-gij-32bit-4.8.5-30.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:9716
    P
    Security update for djvulibre (Important)
    2021-06-04
    oval:org.opensuse.security:def:10262
    P
    Security update for curl (Moderate)
    2021-05-31
    oval:org.opensuse.security:def:10075
    P
    Security update for java-11-openjdk (Important)
    2021-05-11
    oval:org.opensuse.security:def:10247
    P
    Security update for stunnel (Important)
    2021-05-03
    oval:org.opensuse.security:def:9873
    P
    Security update for libzypp, zypper (Moderate)
    2021-03-25
    oval:org.opensuse.security:def:9669
    P
    Security update for ruby2.5 (Important)
    2021-03-24
    oval:org.opensuse.security:def:10423
    P
    Security update for ldb (Important)
    2021-03-24
    oval:org.opensuse.security:def:9850
    P
    Security update for java-1_8_0-openjdk (Moderate)
    2021-03-01
    oval:org.opensuse.security:def:9851
    P
    Security update for java-1_8_0-ibm (Important)
    2021-03-01
    oval:org.opensuse.security:def:9843
    P
    Security update for the Linux Kernel (Important)
    2021-02-19
    oval:org.opensuse.security:def:10200
    P
    Security update for wpa_supplicant (Important)
    2021-02-11
    oval:org.opensuse.security:def:10132
    P
    Security update for openvswitch (Important)
    2021-02-02
    oval:org.opensuse.security:def:9750
    P
    Security update for sudo (Important)
    2021-01-26
    oval:org.opensuse.security:def:16931
    P
    mysql-connector-java-5.1.42-5.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16695
    P
    bash-devel-4.3-83.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:4095
    P
    mysql-connector-java-5.1.42-5.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16868
    P
    libpng12-compat-devel-1.2.50-19.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16780
    P
    libXrandr-devel-1.5.0-6.2 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16904
    P
    libudev-devel-228-155.21 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:16837
    P
    libksba-devel-1.3.0-23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:10574
    P
    mysql-connector-java on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10552
    P
    libtcnative-1-0-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9966
    P
    perl-Tk on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10744
    P
    libid3tag-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17775
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:10512
    P
    libjpeg62-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9901
    P
    libpcsclite1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:17801
    P
    Security update for mysql-connector-java (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10802
    P
    libtirpc-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10593
    P
    rhythmbox on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10824
    P
    mysql-connector-java on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9981
    P
    radvd on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10757
    P
    libmikmod-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:11083
    P
    libvdpau-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10559
    P
    libvirt-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9914
    P
    libruby2_1-2_1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:9919
    P
    libspice-client-glib-2_0-8 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10735
    P
    libgit2-24 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10466
    P
    libXcursor-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10000
    P
    systemtap on GA media (Moderate)
    2020-12-01
    oval:org.cisecurity:def:965
    P
    DSA-3621-1 -- mysql-connector-java -- security update
    2016-08-26
    oval:com.ubuntu.artful:def:20152575000
    V
    CVE-2015-2575 on Ubuntu 17.10 (artful) - medium.
    2015-04-16
    oval:com.ubuntu.trusty:def:20152575000
    V
    CVE-2015-2575 on Ubuntu 14.04 LTS (trusty) - medium.
    2015-04-16
    oval:com.ubuntu.cosmic:def:201525750000000
    V
    CVE-2015-2575 on Ubuntu 18.10 (cosmic) - medium.
    2015-04-16
    oval:com.ubuntu.bionic:def:20152575000
    V
    CVE-2015-2575 on Ubuntu 18.04 LTS (bionic) - medium.
    2015-04-16
    oval:com.ubuntu.xenial:def:20152575000
    V
    CVE-2015-2575 on Ubuntu 16.04 LTS (xenial) - medium.
    2015-04-16
    oval:com.ubuntu.bionic:def:201525750000000
    V
    CVE-2015-2575 on Ubuntu 18.04 LTS (bionic) - medium.
    2015-04-16
    oval:com.ubuntu.cosmic:def:20152575000
    V
    CVE-2015-2575 on Ubuntu 18.10 (cosmic) - medium.
    2015-04-16
    oval:com.ubuntu.xenial:def:201525750000000
    V
    CVE-2015-2575 on Ubuntu 16.04 LTS (xenial) - medium.
    2015-04-16
    oval:com.ubuntu.precise:def:20152575000
    V
    CVE-2015-2575 on Ubuntu 12.04 LTS (precise) - medium.
    2015-04-16
    BACK
    debian debian linux 8.0
    suse linux enterprise desktop 11 sp3
    suse linux enterprise server 11 sp3
    suse linux enterprise server 11 sp3
    suse linux enterprise software development kit 11 sp3
    mysql mysql *
    mysql mysql 5.1.34
    ibm security guardium 10.0
    ibm security guardium 10.0.1
    ibm security guardium 10.1
    ibm security guardium 10.1.2
    ibm security guardium 10.1.3