Internal Operations Vulnerability in MySQL Cluster by Oracle
CVE-2023-21860

6.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 January 2023

Summary

A vulnerability exists in the Oracle MySQL Cluster product, specifically within the internal operations component. An attacker with high privileges who has physical access to the communication segment of the MySQL Cluster can exploit this vulnerability. The successful execution of an attack requires an interactive element from an external party. If successfully exploited, this vulnerability could lead to a complete takeover of the MySQL Cluster. Affected versions include those released before 7.4.38, 7.5.28, 7.6.24, and 8.0.31, necessitating an urgent review of security protocols for installations using these versions.

Affected Version(s)

MySQL Cluster 7.4.38 and prior

MySQL Cluster 7.5.28 and prior

MySQL Cluster 7.6.24 and prior

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.