CVE-2020-14878Oracle Mysql vulnerability

10 documents10 sources
Severity
8.0HIGHNVD
EPSS
0.9%
top 24.33%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21
Latest updateMay 24

Description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the MySQL Server executes to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 8.0 (Confidentiality, Integrity and Avail

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages2 packages

CVEListV5oracle_corporation/mysql_server8.0.21 and prior
NVDoracle/mysql8.0.08.0.21

🔴Vulnerability Details

3
GHSA
GHSA-747m-4qjr-r67x: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth)2022-05-24
OSV
CVE-2020-14878: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth)2020-10-21
CVEList
CVE-2020-14878: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth)2020-10-21

📋Vendor Advisories

5
Ubuntu
MySQL vulnerabilities2020-10-27
Red Hat
mysql: Server: Security: LDAP Auth unspecified vulnerability (CPU Oct 2020)2020-10-20
Oracle
Oracle Oracle MySQL Risk Matrix: Server: Security: LDAP Auth — CVE-2020-148782020-10-15
Microsoft
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: LDAP Auth). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows l2020-10-13
Debian
CVE-2020-14878: mysql-8.0 - Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Se...2020

💬Community

1
Bugzilla
CVE-2020-14878 mysql: Server: Security: LDAP Auth unspecified vulnerability (CPU Oct 2020)2020-10-22
CVE-2020-14878 — Oracle Mysql vulnerability | cvebase