First published: Wed Oct 21 2020(Updated: )
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL Installer | >=8.0.0<=8.0.21 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-14878 is considered a high-severity vulnerability due to its potential for exploitation by low-privileged attackers.
To fix CVE-2020-14878, upgrade your MySQL Server to version 8.0.22 or later.
CVE-2020-14878 affects users of MySQL Server version 8.0.21 and prior.
CVE-2020-14878 can be exploited by attackers with access to the physical communication segment of the MySQL Server.
CVE-2020-14878 affects the LDAP authentication component of MySQL Server.