CVE-2022-21592: Medium severity mysql vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.7.39 and prior and 8.0.29 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-21592.
What is the affected software?
The affected software is Oracle MySQL 5.7.39 and prior, Oracle MySQL 8.0.29 and prior, NetApp OnCommand Insight, and NetApp OnCommand Workflow Automation.
How severe is CVE-2022-21592?
CVE-2022-21592 has a severity score of 4.3, which is considered medium.
How can this vulnerability be exploited?
This vulnerability can be exploited by a low privileged attacker with network access via multiple protocols.
Are there any fixes or patches available for this vulnerability?
For Oracle MySQL, please refer to the Oracle Security Advisory. For NetApp products, please refer to the NetApp Security Advisory.