CVE-2022-21457: Medium severity oracle mysql vulnerability
Last updated 24 July 2024
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data.
External References:
https://www.oracle.com/security-alerts/cpuapr2022.html#AppendixMSQL
— Red Hat
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
— Launchpad
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this MySQL Server vulnerability?
The vulnerability ID is CVE-2022-21457.
What component of Oracle MySQL is affected by this vulnerability?
The Server: PAM Auth Plugin component of Oracle MySQL is affected by this vulnerability.
Which versions of Oracle MySQL are affected by this vulnerability?
Versions 8.0.28 and prior of Oracle MySQL are affected by this vulnerability.
How can an attacker exploit this vulnerability?
An unauthenticated attacker with network access via multiple protocols can exploit this vulnerability to compromise MySQL Server.
What is the severity rating of this vulnerability?
This vulnerability has a severity rating of medium (5.9).