First published: Tue Oct 18 2022(Updated: )
Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell: Core Client). Supported versions that are affected are 8.0.30 and prior. Easily exploitable vulnerability allows unauthenticated attacker with logon to the infrastructure where MySQL Shell executes to compromise MySQL Shell. While the vulnerability is in MySQL Shell, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Shell accessible data. CVSS 3.1 Base Score 4.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle MySQL | >=8.0<=8.0.30 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this MySQL Shell vulnerability is CVE-2022-39402.
The affected component of this vulnerability in MySQL Shell is Shell: Core Client.
Versions 8.0.30 and prior of Oracle MySQL are affected by this vulnerability.
Yes, this MySQL Shell vulnerability is easily exploitable.
An unauthenticated attacker with logon to the infrastructure where MySQL Shell executes can compromise MySQL Shell.
The severity of this MySQL Shell vulnerability is medium with a CVSS score of 4.3.
You can find more information about this MySQL Shell vulnerability at the following link: [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpuoct2022.html).