CVE-2024-20975: Medium severity ORACLE MySQL vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.2.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MySQL Server (Oracle MySQL)to a version that resolves this vulnerability.Fixed in 8.2.0 and prior
Event History
Frequently Asked Questions
What is the severity of CVE-2024-20975?
CVE-2024-20975 has been classified as an easily exploitable vulnerability that poses a significant risk to MySQL Server.
How do I fix CVE-2024-20975?
To fix CVE-2024-20975, it's recommended to upgrade MySQL Server to version 8.2.1 or later.
Who is affected by CVE-2024-20975?
CVE-2024-20975 affects Oracle MySQL Server versions 8.2.0 and prior, as well as components of NetApp OnCommand Insight.
Can a low privileged attacker exploit CVE-2024-20975?
Yes, CVE-2024-20975 allows a low privileged attacker with network access to potentially compromise MySQL Server.
What are the components involved in CVE-2024-20975?
CVE-2024-20975 specifically involves the MySQL Server product, particularly the Optimizer component.