First published: Tue Oct 18 2022(Updated: )
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.27 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL | >=8.0<=8.0.27 | |
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21600.
CVE-2022-21600 has a severity rating of high (7.2).
CVE-2022-21600 affects Oracle MySQL versions 8.0.27 and prior.
CVE-2022-21600 can be exploited by a high privileged attacker with network access via multiple protocols to compromise the MySQL Server.
Yes, you can find references for CVE-2022-21600 at the following links: [NetApp Advisory](https://security.netapp.com/advisory/ntap-20221028-0013/) and [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpuoct2022.html).