PT-2021-20996 · Oracle · Mysql Cluster

Published

2021-10-20

·

Updated

2021-10-26

·

CVE-2021-35592

CVSS v3.1

6.3

Medium

VectorAV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Oracle MySQL Cluster versions 7.5.23 and prior Oracle MySQL Cluster versions 7.6.19 and prior Oracle MySQL Cluster versions 8.0.26 and prior
Description: The issue allows a high-privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Cluster executes to compromise MySQL Cluster. Successful attacks require human interaction from a person other than the attacker and can result in the takeover of MySQL Cluster.
Recommendations: For Oracle MySQL Cluster versions 7.5.23 and prior, update to a version later than 7.5.23. For Oracle MySQL Cluster versions 7.6.19 and prior, update to a version later than 7.6.19. For Oracle MySQL Cluster versions 8.0.26 and prior, update to a version later than 8.0.26.

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-35592
ZDI-21-1228

Affected Products

Mysql Cluster