MySQL Enterprise Monitor 3.2.x < 126.96.36.1999 / 3.3.x < 188.8.131.5292 / 3.4.x < 184.108.40.20625 Multiple Vulnerabilities (October 2017 CPU)
High Nessus Plugin ID 103536
SynopsisA web application running on the remote host is affected by a denial of service vulnerability in apache struts 2.
DescriptionAccording to its self-reported version, the MySQL Enterprise Monitor application running on the remote host is 3.2.x prior to 220.127.116.119, 3.3.x prior to 18.104.22.16892, or 3.4.x prior to 22.214.171.12425.
It is, therefore, affected by multiple vulnerabilities as noted in the October 2017 Critical Patch Update advisory. Please consult the CVRF details for the applicable CVEs for additional information.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to MySQL Enterprise Monitor version 126.96.36.1999 / 188.8.131.5292 / 184.108.40.20625 or later as referenced in the Oracle security advisory.