MySQL Cluster 7.3.x < 7.3.17 DD Subcomponent Arbitrary Data Manipulation (April 2017 CPU)

This script is Copyright (C) 2017 Tenable Network Security, Inc.


Synopsis :

The remote database server is affected by an arbitrary data
manipulation vulnerability.

Description :

The version of MySQL Cluster running on the remote host is 7.3.x prior
to 7.3.17. It is, therefore, affected by an arbitrary data
manipulation vulnerability in the DD subcomponent due to an
unspecified flaw. An authenticated, remote attacker can exploit this
to update, insert, or delete arbitrary data or cause a partial denial
of service condition.

See also :

http://www.nessus.org/u?ff9301b1
http://www.nessus.org/u?54d9438d
http://www.nessus.org/u?08e1362c

Solution :

Upgrade to MySQL Cluster version 7.3.17 or later as referenced in the
April 2017 Oracle Critical Patch Update advisory.

Risk factor :

Medium / CVSS Base Score : 6.5
(CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P)

Family: Databases

Nessus Plugin ID: 99518 ()

Bugtraq ID: 97815

CVE ID: CVE-2017-3304

Ready to Amp Up Your Nessus Experience?

Get Nessus Professional to scan unlimited IPs, run compliance checks & more

Buy Nessus Professional Now