PT-2014-2022 · Oracle+10 · Mysql Server+9

Published

2014-05-12

·

Updated

2025-06-10

·

CVE-2021-2032

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions MySQL Server versions 5.7.32 and prior MySQL Server versions 8.0.22 and prior
Description The issue exists due to insufficient input validation in the Information Schema component of MySQL Server. This allows a remote attacker to gain unauthorized read access to a subset of MySQL Server accessible data via network packets. Successful attacks can result in unauthorized read access to data.
Recommendations For MySQL Server versions 5.7.32 and prior, update to a version later than 5.7.32 to resolve the issue. For MySQL Server versions 8.0.22 and prior, update to a version later than 8.0.22 to resolve the issue. As a temporary workaround, consider restricting network access to the MySQL Server to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2021:3590
ALT-PU-2021-1338
ALT-PU-2021-2380
ALT-PU-2021-3668
BDU:2021-00620
BIT-MARIADB-2021-2032
BIT-MARIADB-MIN-2021-2032
BIT-MYSQL-CLIENT-2021-2032
CESA-2021_3590
CVE-2021-2032
OESA-2021-1113
OESA-2022-1682
OPENSUSE-SU-2022_0131-1
RHSA-2021:3590
RHSA-2021:3811
RHSA-2021_3590
RLSA-2021:3590
USN-4716-1

Affected Products

Alt Linux
Almalinux
Centos
Linuxmint
Mariadb Server
Mysql Server
Red Hat
Rocky Linux
Suse
Ubuntu