First published: Tue Apr 20 2021(Updated: )
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Packaging). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 6.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <5.7.34 | 5.7.34 |
redhat/mysql | <8.0.24 | 8.0.24 |
MySQL | >=8.0.0<=8.0.23 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
netapp snapcenter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-2307 is considered an easily exploitable vulnerability that allows unauthenticated attackers to gain unauthorized access.
To fix CVE-2021-2307, you should upgrade your MySQL Server to version 5.7.34 or later, or version 8.0.24 or later.
CVE-2021-2307 affects MySQL Server versions 5.7.33 and prior as well as 8.0.23 and prior.
CVE-2021-2307 requires the attacker to have logon access to the server infrastructure where MySQL is executed, limiting its remote exploitability.
CVE-2021-2307 impacts the Oracle MySQL Server product, as well as specific deployments such as NetApp Active IQ Unified Manager and OnCommand products.