Vulnerability Name:

CVE-2017-3322 (CCN-120902)

Assigned:2016-12-06
Published:2017-01-17
Updated:2017-07-26
Summary:Vulnerability in the MySQL Cluster component of Oracle MySQL (subcomponent: Cluster: NDBAPI). Supported versions that are affected are 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier and . Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Cluster. CVSS v3.0 Base Score 3.7 (Availability impacts).
CVSS v3 Severity:3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
3.2 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L)
3.2 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Low
CVSS v2 Severity:4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
2.6 Low (CCN CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:N/A:P)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Partial
Vulnerability Type:CWE-noinfo
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-3322

Source: CCN
Type: Oracle CPUJan2017
Oracle Critical Patch Update Advisory - January 2017

Source: CONFIRM
Type: Patch, Vendor Advisory
http://www.oracle.com/technetwork/security-advisory/cpujan2017-2881727.html

Source: BID
Type: UNKNOWN
95574

Source: CCN
Type: BID-95574
Oracle MySQL Cluster CVE-2017-3322 Remote Security Vulnerability

Source: SECTRACK
Type: UNKNOWN
1037640

Source: XF
Type: UNKNOWN
oracle-cpujan2017-cve20173322(120902)

Vulnerable Configuration:Configuration 1:
  • cpe:/a:oracle:mysql_cluster:*:*:*:*:*:*:*:* (Version <= 7.2.25)
  • OR cpe:/a:oracle:mysql_cluster:*:*:*:*:*:*:*:* (Version <= 7.3.14)
  • OR cpe:/a:oracle:mysql_cluster:*:*:*:*:*:*:*:* (Version <= 7.4.12)

  • Configuration CCN 1:
  • cpe:/a:oracle:mysql_cluster:7.2.25:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql_cluster:7.3.14:*:*:*:*:*:*:*
  • OR cpe:/a:oracle:mysql_cluster:7.4.12:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.cisecurity:def:1844
    V
    Vulnerability in the MySQL Cluster 7.2.25 and earlier, 7.3.14 and earlier and 7.4.12 and earlier – CVE-2016-3322
    2017-03-03
    BACK
    oracle mysql cluster *
    oracle mysql cluster *
    oracle mysql cluster *
    oracle mysql cluster 7.2.25
    oracle mysql cluster 7.3.14
    oracle mysql cluster 7.4.12