REDHAT-BUG-2504779: Low severity Oracle MySQL Server vulnerability
Vulnerability in the MySQL Server, MySQL Cluster product of Oracle MySQL (component: Server: Performance Schema). Supported versions that are affected are MySQL Server: 8.4.0-8.4.10, 9.7.0-9.7.1; MySQL Cluster: 8.0.0-8.0.47, 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server, MySQL Cluster. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server, MySQL Cluster accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
Exploitation requires a high-privileged attacker with network access to the affected MySQL Server or MySQL Cluster instance. No user interaction is required, and the attack complexity is low.
What is the potential impact of a successful attack?
A successful attack can give the attacker unauthorized read access to a subset of data accessible through the affected MySQL Server or MySQL Cluster. The provided CVSS vector indicates confidentiality impact only; integrity and availability are not affected.
Which versions are affected?
Affected MySQL Server versions are 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1. Affected MySQL Cluster versions are 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1.