CVE-2021-2006: Medium severity ibm infosphere guardium z/os vulnerability
An unspecified vulnerability in Oracle MySQL Client related to the C API component could allow an authenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
Other sources
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 8.0.19 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Client. CVSS 3.1 Base Score 5.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-2006?
CVE-2021-2006 has been categorized as having high availability impact, leading to a denial of service.
How do I fix CVE-2021-2006?
Fixing CVE-2021-2006 involves applying available patches from the affected software vendors, specifically for Oracle MySQL and IBM Security Guardium.
What products are affected by CVE-2021-2006?
CVE-2021-2006 impacts versions of IBM Security Guardium, Oracle MySQL up to version 8.0.19, and certain versions of NetApp products.
What type of attack can exploit CVE-2021-2006?
CVE-2021-2006 can be exploited by an authenticated attacker using unknown attack vectors to cause a denial of service.
Is CVE-2021-2006 a remote vulnerability?
CVE-2021-2006 is not classified as a remote vulnerability as it requires an authenticated attacker to exploit the issue.