CVE-2019-2923: Medium severity mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2923?
CVE-2019-2923 is rated as an easily exploitable vulnerability allowing unauthenticated attackers to gain access to MySQL Server.
How do I fix CVE-2019-2923?
To fix CVE-2019-2923, it is recommended to upgrade MySQL Server to versions 5.6.46 or later and 5.7.28 or later.
Which MySQL versions are affected by CVE-2019-2923?
Versions 5.6.45 and prior, as well as 5.7.27 and prior of MySQL Server are affected by CVE-2019-2923.
Can CVE-2019-2923 be exploited remotely?
Yes, CVE-2019-2923 can be exploited remotely by unauthenticated attackers with network access.
Is there a patch available for CVE-2019-2923?
Yes, Oracle has released patches for the affected versions of MySQL Server to address CVE-2019-2923.