First published: Wed Jan 20 2021(Updated: )
An unspecified vulnerability in Oracle MySQL Server related to the Server: Optimizer component could allow an authenticated attacker to cause a denial of service resulting in a high availability impact using unknown attack vectors.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <8.0.23 | 8.0.23 |
Oracle MySQL | >=8.0.0<=8.0.22 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapcenter | ||
IBM Security Guardium | <=10.5 | |
IBM Security Guardium | <=10.6 | |
IBM Security Guardium | <=11.0 | |
IBM Security Guardium | <=11.1 | |
IBM Security Guardium | <=11.2 | |
IBM Security Guardium | <=11.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this MySQL Server vulnerability is CVE-2021-2065.
This vulnerability affects the Server: Optimizer component of MySQL Server.
The severity rating of CVE-2021-2065 is 4.9 (medium).
The versions 8.0.22 and prior of MySQL Server are affected by this vulnerability.
This vulnerability can be exploited by a high privileged attacker with network access via multiple protocols to compromise MySQL Server.
The recommended remedy for this vulnerability is to update MySQL Server to version 8.0.23.
Yes, NetApp OnCommand Insight, NetApp OnCommand Workflow Automation, Netapp Snapcenter, and IBM Security Guardium versions 10.5 to 11.3 are also affected by this vulnerability.
You can find more information about this vulnerability at the following references: [IBM X-Force Exchange](https://exchange.xforce.ibmcloud.com/vulnerabilities/195164), [IBM Security Guardium support](https://www.ibm.com/support/pages/node/6455269), and [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujan2021.html#AppendixMSQL).