Analyst readout for executives and security teams
Plain-English summary
This affects Oracle MySQL Connector/J, the Java driver many applications use to talk to MySQL. Versions 5.1.41 and earlier could let a low-privileged network attacker read some accessible data and make unauthorized data changes. The main business risk is data integrity loss in applications carrying the vulnerable connector.
Executive priority
Treat as a medium-priority data integrity issue. Prioritize internet-facing or partner-accessible Java applications that use old Connector/J versions, especially where the application account can modify sensitive business records.
Technical view
Oracle describes CVE-2017-3586 as a MySQL Connectors Connector/J flaw affecting supported versions 5.1.41 and earlier. CVSS 3.0 is 6.4 with network attack vector, low complexity, low privileges, no user interaction, changed scope, and low confidentiality and integrity impact.
Likely exposure
Exposure is most likely in Java applications bundling or depending on MySQL Connector/J 5.1.41 or earlier, including transitive dependencies and packaged server applications. The bundle does not identify specific downstream products beyond possible impact to additional products.
Exploitation context
The source bundle marks KEV as false and provides no cited evidence of active exploitation. Oracle characterizes exploitation as easy, requiring network access and low privileges, with potential unauthorized read and data modification impacts.
Researcher notes
Public details in the bundle are limited to Oracle’s advisory description, CVSS vector, affected version boundary, and vendor references. No CWE, exploit details, or exact fixed Connector/J version is provided in the supplied data.
Mitigation direction
- Inventory Java applications for MySQL Connector/J 5.1.41 or earlier.
- Upgrade or replace affected Connector/J versions using Oracle or distribution vendor guidance.
- Apply relevant Debian package updates if using Debian-maintained Connector/J packages.
- Restrict network paths to database-facing application components where feasible.
- Limit database account privileges used by affected applications.
Validation and detection
- Review dependency manifests, packaged JARs, and build artifacts for Connector/J versions.
- Confirm deployed runtime artifacts no longer include 5.1.41 or earlier.
- Check Debian systems against DSA-3857 package status where applicable.
- Review database logs for unusual reads, updates, inserts, or deletes.
- Verify application database users follow least-privilege access.
Public sources used
Based on public source material and reviewed before publication.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2017-3586 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- 1038287CVE reference · vdb-entry, x_refsource_SECTRACK
- http://www.oracle.com/technetwork/security-advisory/cpuapr2017-3236618.htmlCVE reference · x_refsource_CONFIRM
- DSA-3857CVE reference · vendor-advisory, x_refsource_DEBIAN
- 97982CVE reference · vdb-entry, x_refsource_BID
- 97784CVE reference · vdb-entry, x_refsource_BID
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
