Oracle MySQL Server Vulnerability Allows High Privileged Attackers to Compromise Data
CVE-2024-21244
2.2LOW
Summary
A vulnerability exists in the MySQL Server component of Oracle MySQL that allows a high privileged attacker with network access via multiple protocols to exploit the system. This vulnerability can lead to unauthorized read access to certain data within MySQL Server. Versions impacted include 8.4.2 and earlier, as well as 9.0.1 and earlier. Addressing this issue is crucial for maintaining the confidentiality of data managed by Oracle's MySQL products.
Affected Version(s)
MySQL Server * <= 8.4.2
MySQL Server * <= 9.0.1
References
CVSS V3.1
Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre Database