PT-2014-2022 · Oracle+10 · Mysql Server+9

Publicado

2014-05-12

·

Atualizado

2025-06-10

·

CVE-2021-2032

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MySQL Server versions 5.7.32 and prior MySQL Server versions 8.0.22 and prior
Description The issue exists due to insufficient input validation in the Information Schema component of MySQL Server. This allows a remote attacker to gain unauthorized read access to a subset of MySQL Server accessible data via network packets. Successful attacks can result in unauthorized read access to data.
Recommendations For MySQL Server versions 5.7.32 and prior, update to a version later than 5.7.32 to resolve the issue. For MySQL Server versions 8.0.22 and prior, update to a version later than 8.0.22 to resolve the issue. As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2021:3590
ALT-PU-2021-1338
ALT-PU-2021-2380
ALT-PU-2021-3668
BDU:2021-00620
BIT-MARIADB-2021-2032
BIT-MARIADB-MIN-2021-2032
BIT-MYSQL-CLIENT-2021-2032
CESA-2021_3590
CVE-2021-2032
OESA-2021-1113
OESA-2022-1682
OPENSUSE-SU-2022_0131-1
RHSA-2021:3590
RHSA-2021:3811
RHSA-2021_3590
RLSA-2021:3590
USN-4716-1

Produtos afetados

Alt Linux
Almalinux
Centos
Linuxmint
Mariadb Server
Mysql Server
Red Hat
Rocky Linux
Suse
Ubuntu