First published: Wed Jan 20 2021(Updated: )
An unspecified vulnerability in Oracle MySQL Server related to the Informational Schema component could allow an authenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <5.7.33 | 5.7.33 |
redhat/mysql | <8.0.23 | 8.0.23 |
redhat/mariadb | <10.0.11 | 10.0.11 |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
Oracle MySQL | >=5.7.0<=5.7.32 | |
Oracle MySQL | >=8.0.0<=8.0.22 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter | ||
MariaDB | >=10.0.0<10.0.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-2032 has a low confidentiality impact due to the potential exposure of sensitive information to authenticated attackers.
To mitigate CVE-2021-2032, upgrade to MySQL Server 5.7.33 or 8.0.23, or to MariaDB 10.0.11 or higher.
CVE-2021-2032 affects versions of MySQL Server prior to 5.7.33 and 8.0.23.
Yes, IBM Security Guardium versions up to 11.3 are also affected by CVE-2021-2032.
CVE-2021-2032 involves unknown attack vectors that can be exploited by authenticated attackers.