CVE-2021-2010: Medium severity ibm infosphere guardium z/os vulnerability
An unspecified vulnerability in Oracle MySQL Client related to the C API component could allow an authenticated attacker to cause no confidentiality impact, low integrity impact, and low availability impact.
Other sources
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Client.
External References:
https://www.oracle.com/security-alerts/cpujan2021.html#AppendixMSQL
— Red Hat
Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.50 and prior, 5.7.32 and prior and 8.0.22 and prior. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Client accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Client. CVSS 3.1 Base Score 4.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-2010?
CVE-2021-2010 has a low severity rating due to its limited impact on confidentiality, integrity, and availability.
How do I fix CVE-2021-2010?
To fix CVE-2021-2010, upgrade to the supported versions of MySQL: 5.6.51, 5.7.33, or 8.0.23.
Which MySQL versions are affected by CVE-2021-2010?
CVE-2021-2010 affects MySQL versions prior to 5.6.51, 5.7.33, and 8.0.23.
Is authentication required to exploit CVE-2021-2010?
Yes, an authenticated attacker is necessary to exploit CVE-2021-2010.
What components of Oracle MySQL are impacted by CVE-2021-2010?
CVE-2021-2010 specifically impacts the C API component of the Oracle MySQL Client.