Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Replication). Supported versions that are affected are 5.5.57 and earlier, 5.6.37 and earlier and 5.7.19 and earlier. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 4.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N).
http://www.debian.org/security/2017/dsa-4002
http://www.oracle.com/technetwork/security-advisory/cpuoct2017-3236626.html
http://www.securityfocus.com/bid/101390
http://www.securitytracker.com/id/1039597
https://access.redhat.com/errata/RHSA-2017:3265
https://access.redhat.com/errata/RHSA-2017:3442
https://access.redhat.com/errata/RHSA-2018:0279
https://access.redhat.com/errata/RHSA-2018:0574
https://access.redhat.com/errata/RHSA-2018:2439
https://access.redhat.com/errata/RHSA-2018:2729
https://access.redhat.com/errata/RHSA-2019:1258
https://lists.debian.org/debian-lts-announce/2018/06/msg00015.html
Source: MITRE
Published: 2017-10-19
Updated: 2019-05-21
Type: CWE-200
Base Score: 1.5
Vector: AV:L/AC:M/Au:S/C:P/I:N/A:N
Impact Score: 2.9
Exploitability Score: 2.7
Severity: LOW
Base Score: 4.1
Vector: CVSS:3.0/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
Impact Score: 3.6
Exploitability Score: 0.5
Severity: MEDIUM