First published: Tue Jul 19 2022(Updated: )
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Server accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/mysql | <8.0.29 | 8.0.29 |
Oracle Mysql Server | <=8.0.29 | |
Netapp Active Iq Unified Manager Vmware Vsphere | ||
Netapp Active Iq Unified Manager Windows | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
Netapp Snapcenter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-21455 is medium with a severity value of 4.9.
Oracle MySQL Server versions 8.0.28 and prior are affected by CVE-2022-21455.
A high privileged attacker with network access via multiple protocols can exploit CVE-2022-21455 to compromise MySQL Server.
The recommended fix for CVE-2022-21455 is to update Oracle MySQL Server to version 8.0.29 or later.
You can find more information about CVE-2022-21455 in the references provided: [NetApp Security Advisory](https://security.netapp.com/advisory/ntap-20220729-0004/), [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujul2022.html)