CVE-2021-2021: Medium severity ibm infosphere guardium z/os vulnerability
An unspecified vulnerability in Oracle MySQL Server related to the Server: Optimizer component could allow an authenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server.
External References:
https://www.oracle.com/security-alerts/cpujan2021.html#AppendixMSQL
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-2021?
CVE-2021-2021 has been classified as a denial of service vulnerability that impacts the availability of Oracle MySQL Server.
How do I fix CVE-2021-2021?
To mitigate CVE-2021-2021, upgrade Oracle MySQL Server to version 8.0.23 or a later release.
What software versions are affected by CVE-2021-2021?
CVE-2021-2021 affects multiple versions of Oracle MySQL and the IBM Security Guardium products up to specific versions.
Who can exploit CVE-2021-2021?
CVE-2021-2021 can be exploited by authenticated attackers to cause a denial of service.
What components are impacted by CVE-2021-2021?
CVE-2021-2021 affects the Server: Optimizer component of Oracle MySQL.