CVE-2019-2822Oracle Mysql vulnerability

4 documents4 sources
Severity
7.5HIGHNVD
EPSS
3.3%
top 12.78%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 23
Latest updateMay 24

Description

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Admin / InnoDB Cluster). Supported versions that are affected are 8.0.16 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.0 Base Score 7.5 (Confid

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

CVEListV5oracle_corporation/mysql_server8.0.16 and prior
NVDoracle/mysql8.0.08.0.16

Patches

🔴Vulnerability Details

1
GHSA
GHSA-5929-w48j-r4m7: Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Shell: Admin / InnoDB Cluster)2022-05-24

📋Vendor Advisories

1
Red Hat
mysql: Shell: Admin / InnoDB Cluster unspecified vulnerability (CPU Jul 2019)2019-07-16

💬Community

1
Bugzilla
CVE-2019-2822 mysql: Shell: Admin / InnoDB Cluster unspecified vulnerability (CPU Jul 2019)2019-07-22