{"id":"CVE-2016-3471","description":"Unspecified vulnerability in Oracle MySQL 5.5.45 and earlier and 5.6.26 and earlier allows local users to affect confidentiality, integrity, and availability via vectors related to Server: Option.","cvssScore":7.5,"cvssVersion":"3.1","cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","cvssMetrics":[{"version":"3.1","score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"},{"version":"2.0","score":6.2,"vector":"AV:L/AC:H/Au:N/C:C/I:C/A:C","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"resolved":"NOT-APPLICABLE","published":"2016-07-21","lastModified":"2026-06-17","affectedProducts":[{"vendor":"oracle","product":"mysql","versionStart":"\u003e=5.5.0","versionEnd":"\u003c=5.5.45"},{"vendor":"oracle","product":"mysql","versionStart":"\u003e=5.6.0","versionEnd":"\u003c=5.6.26"},{"vendor":"redhat","product":"enterprise linux","version":"6.0"},{"vendor":"redhat","product":"enterprise linux","version":"7.0"},{"vendor":"mariadb","product":"mariadb","versionStart":"\u003e=5.5.0","versionEnd":"\u003c5.5.46"},{"vendor":"mariadb","product":"mariadb","versionStart":"\u003e=10.0.0","versionEnd":"\u003c10.0.22"},{"vendor":"mariadb","product":"mariadb","versionStart":"\u003e=10.1.0","versionEnd":"\u003c10.1.9"}],"totalAffectedProducts":3,"references":[{"url":"http://rhn.redhat.com/errata/RHSA-2016-0534.html","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://rhn.redhat.com/errata/RHSA-2016-0705.html","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://rhn.redhat.com/errata/RHSA-2016-1480.html","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://rhn.redhat.com/errata/RHSA-2016-1481.html","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]},{"url":"http://www.oracle.com/technetwork/security-advisory/cpujul2016-2881720.html","source":"secalert_us@oracle.com","tags":["Patch","Vendor Advisory"]},{"url":"http://www.securityfocus.com/bid/91787","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securityfocus.com/bid/91913","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1036362","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://access.redhat.com/errata/RHSA-2016:1132","source":"secalert_us@oracle.com","tags":["Third Party Advisory"]}],"reasoning":{"decidingSource":"h2-history","decidingReason":"Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"NOT-APPLICABLE","detail":"Found in legacy manual classifications","decisive":true}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update July 2016","releaseType":"CPU","quarter":"2016-Q3","url":"https://www.oracle.com/security-alerts/cpujul2016.html","products":[{"product":"Oracle MySQL","component":"Server: Option","affectedVersions":"5.5.45 and earlier, 5.6.26 and earlier"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** SERVER: OPTION\n\n**Products:** MYSQL, MYSQL SERVER, ORACLE MYSQL","signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.00364,"percentile":0.29799},"ssvc":{"available":true,"exploitation":"none","automatable":"no","technicalImpact":"total"}}