Resource exhaustion in MySQL Server - CVE-2018-3247

 

Resource exhaustion in MySQL Server - CVE-2018-3247

Published: June 29, 2023


Vulnerability identifier: #VU77802
CSH Severity: Low
CVSS v4: 7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-3247
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote privileged user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A remote privileged user can cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data.


Affected software

MySQL Server
Tivoli Network Manager IP Edition

How to mitigate CVE-2018-3247

Install updates from vendor's website.


External References

Related Security Bulletins