VYPR
High severity8.5NVD Advisory· Published Apr 24, 2017· Updated May 13, 2026

CVE-2017-3523

CVE-2017-3523

Description

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mysql:mysql-connector-javaMaven
< 5.1.415.1.41

Affected products

2
  • cpe:2.3:a:oracle:connector\/j:*:*:*:*:*:*:*:*
    Range: <=5.1.40
  • Oracle Corporation/MySQL Connectorsv5
    Range: 5.1.40 and earlier

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.