First published: Wed Apr 18 2018(Updated: )
Last updated 24 July 2024
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mariadb-10.0 | ||
debian/mysql-5.5 | ||
debian/mysql-5.7 | ||
redhat/mysql | <5.5.60 | 5.5.60 |
redhat/mysql | <5.6.40 | 5.6.40 |
redhat/mysql | <5.7.22 | 5.7.22 |
redhat/mariadb | <5.5.60 | 5.5.60 |
redhat/mariadb | <10.2.15 | 10.2.15 |
redhat/mariadb | <10.1.33 | 10.1.33 |
redhat/mariadb | <10.0.35 | 10.0.35 |
Debian | =7.0 | |
Debian | =8.0 | |
Debian | =9.0 | |
NetApp Active IQ Unified Manager | >=7.3 | |
NetApp Active IQ Unified Manager for VMware vSphere | >=9.5 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter | ||
Ubuntu | =12.04 | |
Ubuntu | =14.04 | |
Ubuntu | =16.04 | |
Ubuntu | =17.10 | |
Ubuntu | =18.04 | |
MariaDB | >=5.5.0<5.5.60 | |
MariaDB | >=10.0.0<10.0.35 | |
MariaDB | >=10.1.0<10.1.33 | |
MariaDB | >=10.2.0<10.2.15 | |
Oracle MySQL | >=5.5.0<5.5.59 | |
Oracle MySQL | >=5.6.0<5.6.39 | |
Oracle MySQL | >=5.7.0<5.7.21 | |
Red Hat OpenStack for IBM Power | =12 | |
Red Hat Enterprise Linux Desktop | =7.0 | |
Red Hat Enterprise Linux Server EUS | =7.5 | |
Red Hat Enterprise Linux Server EUS | =7.6 | |
Red Hat Enterprise Linux Server EUS | =7.7 | |
Red Hat Enterprise Linux Server | =7.0 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Server | =7.6 | |
Red Hat Enterprise Linux Server | =7.7 | |
Red Hat Enterprise Linux Workstation | =7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-2781 is considered an easily exploitable vulnerability that allows high privileged attackers with network access to gain unauthorized access.
To fix CVE-2018-2781, upgrade MySQL Server to version 5.5.60, 5.6.40, or 5.7.22 or later.
Versions affected by CVE-2018-2781 include MySQL 5.5.59 and prior, 5.6.39 and prior, and 5.7.21 and prior.
Yes, certain versions of MariaDB, particularly those that align with the affected MySQL versions, are also vulnerable.
More information about CVE-2018-2781 can usually be found in security advisories and vulnerability databases.