Vulnerability in MySQL Client from Oracle Affecting Data Access
CVE-2024-21209

2LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

A security vulnerability exists in Oracle's MySQL Client, specifically affecting the mysqldump component. This issue allows an attacker with high privileges and network access to target the MySQL Client. While exploiting this vulnerability is challenging, it requires assistance from an external user, leading to potential unauthorized access to sensitive data. The affected versions include 8.4.2 and earlier, along with 9.0.1 and earlier. Timely updates and security measures are essential to mitigate the risk associated with this vulnerability.

Affected Version(s)

MySQL Client * <= 8.4.2

MySQL Client * <= 9.0.1

References

CVSS V3.1

Score:
2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.