LiveActive security incident?Get immediate response
CVE Record

CVE-2017-3586: Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J).

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.0 Base Score 6.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N).

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's Takemoderate

Analyst readout for executives and security teams

Plain-English summary

This affects Oracle MySQL Connector/J, the Java driver many applications use to talk to MySQL. Versions 5.1.41 and earlier could let a low-privileged network attacker read some accessible data and make unauthorized data changes. The main business risk is data integrity loss in applications carrying the vulnerable connector.

Executive priority

Treat as a medium-priority data integrity issue. Prioritize internet-facing or partner-accessible Java applications that use old Connector/J versions, especially where the application account can modify sensitive business records.

Technical view

Oracle describes CVE-2017-3586 as a MySQL Connectors Connector/J flaw affecting supported versions 5.1.41 and earlier. CVSS 3.0 is 6.4 with network attack vector, low complexity, low privileges, no user interaction, changed scope, and low confidentiality and integrity impact.

Likely exposure

Exposure is most likely in Java applications bundling or depending on MySQL Connector/J 5.1.41 or earlier, including transitive dependencies and packaged server applications. The bundle does not identify specific downstream products beyond possible impact to additional products.

Exploitation context

The source bundle marks KEV as false and provides no cited evidence of active exploitation. Oracle characterizes exploitation as easy, requiring network access and low privileges, with potential unauthorized read and data modification impacts.

Researcher notes

Public details in the bundle are limited to Oracle’s advisory description, CVSS vector, affected version boundary, and vendor references. No CWE, exploit details, or exact fixed Connector/J version is provided in the supplied data.

Mitigation direction

  • Inventory Java applications for MySQL Connector/J 5.1.41 or earlier.
  • Upgrade or replace affected Connector/J versions using Oracle or distribution vendor guidance.
  • Apply relevant Debian package updates if using Debian-maintained Connector/J packages.
  • Restrict network paths to database-facing application components where feasible.
  • Limit database account privileges used by affected applications.

Validation and detection

  • Review dependency manifests, packaged JARs, and build artifacts for Connector/J versions.
  • Confirm deployed runtime artifacts no longer include 5.1.41 or earlier.
  • Check Debian systems against DSA-3857 package status where applicable.
  • Review database logs for unusual reads, updates, inserts, or deletes.
  • Verify application database users follow least-privilege access.
Prepared
Confidence
medium
Sources
5

Based on public source material and reviewed before publication.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2017-3586 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
6Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Oracle CorporationMySQL Connectors5.1.41 and earlierListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.