REDHAT-BUG-2460275: Low severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Information Schema). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict network access to MySQL Server: enforce firewall/ACL rules and network segmentation to allow connections only from trusted IPs/networks and management hosts, and block unneeded protocols/ports to reduce exposure to remote attackers (high-privilege or otherwise).
Event History
Frequently Asked Questions
What is the severity of REDHAT-BUG-2460275?
The severity of REDHAT-BUG-2460275 is classified as low.
How do I fix REDHAT-BUG-2460275?
To fix REDHAT-BUG-2460275, upgrade your MySQL Server to a non-affected version.
Which versions of Oracle MySQL are affected by REDHAT-BUG-2460275?
The affected versions are Oracle MySQL 8.0.0 to 8.0.45, 8.4.0 to 8.4.8, and 9.0.0 to 9.6.0.
Who is impacted by REDHAT-BUG-2460275?
High privileged attackers with network access via multiple protocols can exploit REDHAT-BUG-2460275.
Is REDHAT-BUG-2460275 easily exploitable?
Yes, REDHAT-BUG-2460275 is considered easily exploitable.