PT-2021-6421 · Oracle+1 · Mysql Cluster+1
Lucas Leong
+1
·
Published
2021-07-23
·
Updated
2023-05-30
·
CVE-2022-21333
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle MySQL Cluster versions 7.4.34 and prior
Oracle MySQL Cluster versions 7.5.24 and prior
Oracle MySQL Cluster versions 7.6.20 and prior
Oracle MySQL Cluster versions 8.0.27 and prior
Description
The issue is related to insufficient validation of input data in the MySQL Cluster product, allowing a high-privileged attacker with access to the physical communication segment to compromise the MySQL Cluster. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized read access to a subset of MySQL Cluster accessible data and a partial denial of service (DOS) of MySQL Cluster.
Recommendations
For versions 7.4.34 and prior, update to a version later than 7.4.34 to resolve the issue.
For versions 7.5.24 and prior, update to a version later than 7.5.24 to resolve the issue.
For versions 7.6.20 and prior, update to a version later than 7.6.20 to resolve the issue.
For versions 8.0.27 and prior, update to a version later than 8.0.27 to resolve the issue.
As a temporary workaround, consider restricting access to the MySQL Cluster to minimize the risk of exploitation.
Fix
RCE
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Mysql Cluster