PT-2021-20994 · Oracle · Mysql Cluster
Published
2021-10-20
·
Updated
2021-10-26
·
CVE-2021-35590
CVSS v2.0
6.5
Medium
| Vector | AV:A/AC:H/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Oracle MySQL Cluster versions 7.4.33 and prior
Oracle MySQL Cluster versions 7.5.23 and prior
Oracle MySQL Cluster versions 7.6.19 and prior
Oracle MySQL Cluster versions 8.0.26 and prior
Description:
The issue allows a high-privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker and can result in the takeover of MySQL Cluster.
Recommendations:
For versions 7.4.33 and prior, update to a version later than 7.4.33.
For versions 7.5.23 and prior, update to a version later than 7.5.23.
For versions 7.6.19 and prior, update to a version later than 7.6.19.
For versions 8.0.26 and prior, update to a version later than 8.0.26.
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mysql Cluster