CVE-2022-21278: High severity oracle mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data.
External References:
https://www.oracle.com/security-alerts/cpujan2022.html#AppendixMSQL
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.26 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server as well as unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.1 Base Score 7.1 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H).
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-21278?
CVE-2022-21278 is classified as an easily exploitable vulnerability that allows a low privileged attacker to compromise MySQL Server.
How do I fix CVE-2022-21278?
To fix CVE-2022-21278, upgrade to MySQL Server version 8.0.27 or later.
Which MySQL Server versions are affected by CVE-2022-21278?
CVE-2022-21278 affects MySQL Server versions 8.0.26 and earlier.
Can CVE-2022-21278 be exploited remotely?
Yes, CVE-2022-21278 can be exploited by an attacker with network access.
What component of MySQL Server is involved in CVE-2022-21278?
CVE-2022-21278 involves a vulnerability in the MySQL Server component related to the optimizer.