CVE Vulnerabilities

CVE-2022-21363

Published: Jan 19, 2022 | Modified: Nov 21, 2024
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6 MEDIUM
AV:N/AC:M/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
6.6 MODERATE
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Ubuntu
MEDIUM

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).

Affected Software

Name Vendor Start Version End Version
Mysql_connectors Oracle 8.0.0 (including) 8.0.27 (including)
Red Hat build of Quarkus 2.7.5 RedHat mysql-connector-java *
Red Hat Fuse 7.11 RedHat mysql-connector-java *
Red Hat JBoss Enterprise Application Platform 7 RedHat mysql-connector-java *
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8 RedHat eap7-wildfly-0:7.4.5-3.GA_redhat_00001.1.el8eap *
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7 RedHat eap7-wildfly-0:7.4.5-3.GA_redhat_00001.1.el7eap *
RHPAM 7.13.1 async RedHat mysql-connector-java *
Mysql-connector-java Ubuntu bionic *
Mysql-connector-java Ubuntu trusty *
Mysql-connector-java Ubuntu trusty/esm *
Mysql-connector-java Ubuntu xenial *

References