First published: Tue Apr 16 2024(Updated: )
Vulnerability in the MySQL Cluster product of Oracle MySQL (component: Cluster: General). Supported versions that are affected are 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior and 8.3.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Cluster accessible data. CVSS 3.1 Base Score 2.2 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
MySQL | >=7.5.0<=7.5.33 | |
MySQL | >=7.6.0<=7.6.29 | |
MySQL | >=8.0.0<=8.0.36 | |
MySQL | >=8.1.0<=8.3.0 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
netapp active iq unified manager windows | ||
NetApp OnCommand Insight | ||
NetApp OnCommand Workflow Automation | ||
NetApp SnapCenter |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21101 is classified as a difficult-to-exploit vulnerability, primarily affecting high-privileged attackers with network access.
To remediate CVE-2024-21101, upgrade to the latest versions of MySQL Cluster beyond 7.5.33, 7.6.29, 8.0.36, and 8.3.0.
CVE-2024-21101 affects MySQL Cluster versions 7.5.33 and prior, 7.6.29 and prior, 8.0.36 and prior, and 8.3.0 and prior.
CVE-2024-21101 specifically affects the Cluster product component of Oracle MySQL.
CVE-2024-21101 requires network access for exploitation, making it a remote vulnerability.