CVE-2021-2042: Low severity ibm infosphere guardium z/os vulnerability
An unspecified vulnerability in Oracle MySQL Server related to the InnoDB component could allow an authenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data.
External References:
https://www.oracle.com/security-alerts/cpujan2021.html#AppendixMSQL
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-2042?
CVE-2021-2042 has a low confidentiality impact due to the vulnerability allowing sensitive information disclosure.
Who is affected by CVE-2021-2042?
CVE-2021-2042 affects Oracle MySQL Server, specifically the InnoDB component, as well as IBM's Security Guardium products.
How do I fix CVE-2021-2042?
To mitigate CVE-2021-2042, upgrade Oracle MySQL to version 8.0.22 or later, and ensure IBM Security Guardium is updated to supported versions.
What types of attacks are possible with CVE-2021-2042?
CVE-2021-2042 can be exploited by authenticated attackers using unknown vectors to gain access to sensitive information.
What is the impact of CVE-2021-2042 on confidentiality?
CVE-2021-2042 results in a low confidentiality impact, allowing unauthorized disclosure of sensitive data.