CVE-2019-2814Oracle Mysql vulnerability

6 documents5 sources
Severity
2.2LOWNVD
EPSS
0.4%
top 38.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data. CVSS 3.0 Base Score 2.2 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 0.7 | Impact: 1.4

Affected Packages3 packages

CVEListV5oracle_corporation/mysql_server8.0.16 and prior
NVDoracle/mysql8.0.08.0.16

Also affects: Enterprise Linux 8.0, 8.1, 8.2, 8.4, 8.6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-j6qp-fmgx-hf26: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB)2022-05-24
CVEList
CVE-2019-2814: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: InnoDB)2019-07-23

📋Vendor Advisories

1
Red Hat
mysql: InnoDB unspecified vulnerability (CPU Jul 2019)2019-07-16

💬Community

2
Bugzilla
CVE-2019-2814 mysql: InnoDB unspecified vulnerability (CPU Jul 2019)2019-07-22
Bugzilla
CVE-2019-6283 libsass: heap-based buffer over-read in Sass::Prelexer::parenthese_scope in prelexer.hpp2019-01-23
CVE-2019-2814 — Oracle Mysql vulnerability | cvebase