CVE-2022-21363

CWE-2808 documents7 sources
Severity
6.6MEDIUM
EPSS
1.0%
top 22.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 19
Latest updateJan 20

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.7 | Impact: 5.9

Affected Packages4 packages

NVDoracle/mysql_connectors8.0.08.0.27
CVEListV5oracle_corporation/mysql_connectors8.0.27 and prior
NVDquarkus/quarkus< 2.7.0

🔴Vulnerability Details

4
OSV
Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java2022-01-20
GHSA
Improper Handling of Insufficient Permissions or Privileges in MySQL Connectors Java2022-01-20
CVEList
CVE-2022-21363: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)2022-01-19
OSV
CVE-2022-21363: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)2022-01-19

📋Vendor Advisories

3
Red Hat
mysql-connector-java: Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors2022-01-18
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/J — CVE-2022-213632022-01-15
Microsoft
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privil2022-01-11
CVE-2022-21363 (MEDIUM CVSS 6.6) | Vulnerability in the MySQL Connecto | cvebase.io