5.3
CVE-2023-21971
- EPSS 1.29%
- Veröffentlicht 18.04.2023 20:15:16
- Zuletzt bearbeitet 21.11.2024 07:44:01
- Erkennungen
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Oracle ≫ Communications Cloud Native Core Binding Support Function Version 22.4.0
Oracle ≫ Communications Cloud Native Core Binding Support Function Version 23.1.0
Oracle ≫ Communications Cloud Native Core Policy Version 22.4.0
Oracle ≫ Communications Cloud Native Core Policy Version 23.1.0
Oracle ≫ Mysql Connectors Version >= 8.0.0 <= 8.0.32
Netapp ≫ Active Iq Unified Manager Version - SwPlatform linux
Netapp ≫ Active Iq Unified Manager Version - SwPlatform vmware_vsphere
Netapp ≫ Active Iq Unified Manager Version - SwPlatform windows
Netapp ≫ Oncommand Insight Version -
Netapp ≫ Snapcenter Version -
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.29% | 0.664 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Oracle | 5.3 | 0.5 | 4.7 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H
|
https://security.netapp.com/advisory/ntap-20230427-0007/
https://www.oracle.com/security-alerts/cpujul2023.html
https://www.oracle.com/security-alerts/cpuapr2023.html
https://security.netapp.com/advisory/ntap-20230427-0010/