First published: Wed Jan 20 2021(Updated: )
An unspecified vulnerability in Oracle MySQL Server related to the InnoDB component could allow an authenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <8.0.22 | 8.0.22 |
IBM InfoSphere Guardium z/OS | <=10.5 | |
IBM InfoSphere Guardium z/OS | <=10.6 | |
IBM InfoSphere Guardium z/OS | <=11.0 | |
IBM InfoSphere Guardium z/OS | <=11.1 | |
IBM InfoSphere Guardium z/OS | <=11.2 | |
IBM InfoSphere Guardium z/OS | <=11.3 | |
Oracle MySQL | >=8.0.0<=8.0.21 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-2042 has a low confidentiality impact due to the vulnerability allowing sensitive information disclosure.
CVE-2021-2042 affects Oracle MySQL Server, specifically the InnoDB component, as well as IBM's Security Guardium products.
To mitigate CVE-2021-2042, upgrade Oracle MySQL to version 8.0.22 or later, and ensure IBM Security Guardium is updated to supported versions.
CVE-2021-2042 can be exploited by authenticated attackers using unknown vectors to gain access to sensitive information.
CVE-2021-2042 results in a low confidentiality impact, allowing unauthorized disclosure of sensitive data.