PT-2016-1074 · Oracle · Solaris Cluster+1
Published
2016-01-19
·
Updated
2016-12-07
·
CVE-2016-0417
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Solaris Cluster versions 3.3 and 4.2
Description
The issue is related to errors in the code of the HA for MySQL component in Solaris Cluster, which can be exploited to gain read, modify, add, or delete access to data, or cause a partial denial of service. It affects the confidentiality, integrity, and availability of the system via vectors related to HA for MySQL.
Recommendations
For Solaris Cluster version 3.3, update to a version that includes the fix for this issue.
For Solaris Cluster version 4.2, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the HA for MySQL component to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mysql Server
Solaris Cluster