CVE-2017-3304 is a vulnerability in the MySQL Cluster component of Oracle MySQL, affecting versions 7.2.27 and earlier, 7.3.16 and earlier, 7.4.14 and earlier, and 7.5.5 and earlier. This easily exploitable flaw allows a low-privileged attacker with network access to compromise the MySQL Cluster. Successful attacks can lead to unauthorized data modification (update, insert, delete) and a partial denial of service, as reflected by its CVSS 3.0 Base Score of 5.4 (Medium). There is no known active exploitation, publicly available exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 7.2.27CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* | ||
<= 7.3.16CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* | ||
<= 7.4.14CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* | ||
<= 7.5.5CPE matchmatch criteria | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.