CVE-2021-2016Deserialization of Untrusted Data in Oracle Mysql

Severity
4.9MEDIUMNVD
EPSS
0.4%
top 42.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateJul 30

Description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.19 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector:

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 1.2 | Impact: 3.6

Affected Packages2 packages

CVEListV5oracle_corporation/mysql_server8.0.19 and prior
NVDoracle/mysql8.0.08.0.19

Also affects: Fedora 32, 33

🔴Vulnerability Details

3
GHSA
GHSA-c34q-4vv7-8478: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)2022-05-24
OSV
CVE-2021-2016: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)2021-01-20
CVEList
CVE-2021-2016: Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer)2021-01-20

💥Exploits & PoCs

1
Metasploit
Microsoft Exchange ProxyLogon Collector

🔍Detection Rules

1
Elastic
Microsoft Exchange Server UM Spawning Suspicious Processes

📋Vendor Advisories

10
Oracle
Oracle Oracle Insurance Applications Risk Matrix: Development tools (Apache Commons FileUpload) — CVE-2016-10000312021-10-15
Red Hat
7: Incomplete fix of CVE-2016-4978 in HornetQ library2021-10-05
Red Hat
libzapojit: missing TLS certificate verification2021-08-22
Drupal
Drupal core - Moderately critical - Cross Site Scripting - SA-CORE-2021-0032021-05-26
Oracle
Oracle Oracle Siebel CRM Risk Matrix: UIF Open UI (jQuery UI) — CVE-2016-71032021-04-15

🕵️Threat Intelligence

3
Bleepingcomputer
UK govt links 2021 Electoral Commission breach to Exchange server2024-07-30
Securelist
MysterySnail attacks with Windows zero-day2021-10-12
Trendmicro
FormBook Adds Latest Office 365 0-Day Vulnerability CVE-2021-40444 to Its Arsenal2021-09-29
CVE-2021-2016 — Deserialization of Untrusted Data | cvebase