MySQL Enterprise Monitor 3.2.x < 184.108.40.2069 / 3.3.x < 220.127.116.1192 / 3.4.x < 18.104.22.16825 Multiple Vulnerabilities (October 2017 CPU)
Medium Nessus Plugin ID 103536
SynopsisA web application running on the remote host is affected by a denial of service vulnerability in apache struts 2.
DescriptionAccording to its self-reported version, the MySQL Enterprise Monitor application running on the remote host is 3.2.x prior to 22.214.171.1249, 3.3.x prior to 126.96.36.19992, or 3.4.x prior to 188.8.131.5225.
It is, therefore, affected by multiple vulnerabilities as noted in the October 2017 Critical Patch Update advisory. Please consult the CVRF details for the applicable CVEs for additional information.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
SolutionUpgrade to MySQL Enterprise Monitor version 184.108.40.2069 / 220.127.116.1192 / 18.104.22.16825 or later as referenced in the Oracle security advisory.