First published: Wed Jan 20 2021(Updated: )
An unspecified vulnerability in Oracle MySQL Server related to the Server: Optimizer component could allow an authenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
Oracle MySQL | >=8.0.0<=8.0.19 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter | ||
Fedora | =32 | |
Fedora | =33 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-2016 has not been explicitly stated but it can lead to a denial of service affecting high availability.
To fix CVE-2021-2016, it is essential to apply the latest security patches provided by Oracle for MySQL Server.
CVE-2021-2016 affects various versions of Oracle MySQL Server, including versions between 8.0.0 and 8.0.19, as well as several IBM and NetApp products.
CVE-2021-2016 requires authentication, which means it cannot be exploited remotely without access credentials.
While CVE-2021-2016 is not classified as critical, it poses significant risks due to potential denial of service.