Oracle MySQL Server Vulnerability Allows High Privileged Attackers to Compromise Data
CVE-2024-21244

2.2LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 October 2024

Summary

A vulnerability exists in the MySQL Server component of Oracle MySQL that allows a high privileged attacker with network access via multiple protocols to exploit the system. This vulnerability can lead to unauthorized read access to certain data within MySQL Server. Versions impacted include 8.4.2 and earlier, as well as 9.0.1 and earlier. Addressing this issue is crucial for maintaining the confidentiality of data managed by Oracle's MySQL products.

Affected Version(s)

MySQL Server * <= 8.4.2

MySQL Server * <= 9.0.1

References

CVSS V3.1

Score:
2.2
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre Database
.