Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-21971

Опубликовано: 19 апр. 2023
Источник: redhat
CVSS3: 5.3

Описание

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).

A vulnerability was found in MySQL Connector. Successful attacks of this vulnerability can result in the unauthorized ability to cause a hang or frequently repeatable crash, resulting in complete denial of service of MySQL Connectors. This issue can also result in an unauthorized update, insert or delete access to some of the MySQL Connectors' accessible data, and unauthorized read access to a subset of MySQL Connectors' accessible data.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
A-MQ Clients 2mysql-connector-javaNot affected
Red Hat build of Debezium 1mysql-connector-javaNot affected
Red Hat build of Quarkusmysql/mysql-connector-javaNot affected
Red Hat Data Grid 8mysql-connector-javaNot affected
Red Hat Decision Manager 7mysql-connector-javaOut of support scope
Red Hat Enterprise Linux 6mysql-connector-javaOut of support scope
Red Hat Enterprise Linux 7mysql-connector-javaOut of support scope
Red Hat Fuse 7mysql-connector-javaOut of support scope
Red Hat Integration Camel K 1mysql-connector-javaNot affected
Red Hat JBoss Data Grid 7mysql-connector-javaOut of support scope

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-410
https://bugzilla.redhat.com/show_bug.cgi?id=2196673mysql-connector-java: Connector/J unspecified vulnerability (CPU April 2023)

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.3
ubuntu
около 2 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).

CVSS3: 5.3
nvd
около 2 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).

CVSS3: 5.3
debian
около 2 лет назад

Vulnerability in the MySQL Connectors product of Oracle MySQL (compone ...

suse-cvrf
почти 2 года назад

Security update for mysql-connector-java

suse-cvrf
около 2 лет назад

Security update for mysql-connector-java

5.3 Medium

CVSS3