MySQL Cluster Vulnerability in Oracle MySQL Products
CVE-2022-21357

2.9LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 January 2022

Summary

This vulnerability in the MySQL Cluster component of Oracle MySQL allows an attacker with high privileges and access to the physical communication segment to compromise the MySQL Cluster. Exploitation of this weakness requires interaction from another user, making it difficult to execute. Successful attacks may lead to unauthorized read access to a portion of the data within the MySQL Cluster and could enable a partial denial of service, affecting the availability of the cluster.

Affected Version(s)

MySQL Cluster 7.4.34 and prior

MySQL Cluster 7.5.24 and prior

MySQL Cluster 7.6.20 and prior

References

CVSS V3.1

Score:
2.9
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.