PT-2022-5282 · Mysql Server · Mysql Installer

Ycdxsb

·

Published

2022-10-18

·

Updated

2022-10-20

·

CVE-2022-39404

CVSS v2.0

4.3

Medium

VectorAV:L/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MySQL Installer versions 1.6.3 and prior
Description The issue allows a low-privileged attacker with logon to the infrastructure where MySQL Installer executes to compromise MySQL Installer. Successful attacks require human interaction from a person other than the attacker and can result in unauthorized update, insert, or delete access to some of MySQL Installer's accessible data, as well as unauthorized read access to a subset of MySQL Installer's accessible data. Additionally, it can cause a partial denial of service (partial DOS) of MySQL Installer.
Recommendations For versions 1.6.3 and prior, update to a version later than 1.6.3 to resolve the issue. As a temporary workaround, consider restricting access to the MySQL Installer to minimize the risk of exploitation.

Fix

RCE

Weakness Enumeration

Related Identifiers

BDU:2022-06566
CVE-2022-39404

Affected Products

Mysql Installer