Vulnerability in MySQL Cluster by Oracle Affecting Multiple Versions
CVE-2022-21490

6.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 April 2022

Summary

This vulnerability affects the MySQL Cluster product of Oracle MySQL, where a privileged attacker with access to the physical communication segment of the hardware running the MySQL Cluster may exploit the weakness with human interaction from a user different from the attacker. Successful exploitation could lead to complete compromise of the MySQL Cluster environment, allowing unauthorized access and control over sensitive data and operations.

Affected Version(s)

MySQL Cluster 7.4.35 and prior

MySQL Cluster 7.5.25 and prior

MySQL Cluster 7.6.21 and prior

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.