CVE-2019-2911: Medium severity mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data.
External References:
http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: Information Schema). Supported versions that are affected are 5.6.45 and prior, 5.7.27 and prior and 8.0.17 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2911?
CVE-2019-2911 is considered an easily exploitable vulnerability that allows high-privileged attackers with network access to potentially compromise MySQL servers.
Which MySQL versions are affected by CVE-2019-2911?
CVE-2019-2911 affects MySQL versions 5.6.45 and earlier, 5.7.27 and earlier, and 8.0.17 and earlier.
How do I fix CVE-2019-2911?
To fix CVE-2019-2911, upgrade your MySQL server to versions 5.6.46, 5.7.28, or 8.0.18 or later.
What types of attackers can exploit CVE-2019-2911?
CVE-2019-2911 can be exploited by attackers with high privileges and network access to the MySQL database.
Is CVE-2019-2911 limited to Oracle MySQL servers?
While primarily associated with Oracle MySQL servers, CVE-2019-2911 may also impact other applications utilizing affected MySQL versions.