4.3

CVE-2021-2007

Vulnerability in the MySQL Client product of Oracle MySQL (component: C API). Supported versions that are affected are 5.6.47 and prior, 5.7.29 and prior and 8.0.19 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Client. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Client accessible data. CVSS 3.1 Base Score 3.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N).

Data is provided by the National Vulnerability Database (NVD)
OracleMysql Version >= 5.6.0 <= 5.6.47
OracleMysql Version >= 5.7.0 <= 5.7.29
OracleMysql Version >= 8.0.0 <= 8.0.19
FedoraprojectFedora Version32
FedoraprojectFedora Version33
NetappActive Iq Unified Manager Version- SwPlatformvmware_vsphere
NetappActive Iq Unified Manager Version- SwPlatformwindows
NetappOncommand Insight Version-
MariadbMariadb Version >= 5.5.0 < 5.5.65
MariadbMariadb Version >= 10.1.0 < 10.1.41
MariadbMariadb Version >= 10.2.0 < 10.2.26
MariadbMariadb Version >= 10.3.0 < 10.3.17
MariadbMariadb Version >= 10.4.0 < 10.4.7
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.49% 0.649
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
secalert_us@oracle.com 3.7 2.2 1.4
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N