Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-21363

Опубликовано: 18 янв. 2022
Источник: redhat
CVSS3: 6.6

Описание

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Debezium 1mysql-connector-javaAffected
Red Hat Enterprise Linux 6mysql-connector-javaOut of support scope
Red Hat Enterprise Linux 7mysql-connector-javaOut of support scope
Red Hat Integration Camel K 1mysql-connector-javaNot affected
Red Hat Integration Camel Quarkus 1mysql-connector-javaNot affected
Red Hat JBoss Data Virtualization 6mysql-connector-javaOut of support scope
Red Hat JBoss Enterprise Application Platform 6mysql-connector-javaOut of support scope
Red Hat JBoss Fuse 6mysql-connector-javaOut of support scope
Red Hat OpenShift Container Platform 4openshift4/ose-metering-prestoAffected
Red Hat Satellite 6candlepinFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-280
https://bugzilla.redhat.com/show_bug.cgi?id=2047343mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors

6.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.6
ubuntu
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
nvd
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS3: 6.6
msrc
около 4 лет назад

Описание отсутствует

CVSS3: 6.6
debian
около 4 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...

CVSS3: 6.6
github
около 4 лет назад

Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java

6.6 Medium

CVSS3