VDB

CISA-2019-2791

CISA-2019-2791 PUBLISHED

Reported by oracle · Published July 23, 2019

Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Audit Plug-in). Supported versions that are affected are 5.7.26 and prior and 8.0.16 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).

Affected Products

VendorProductVersions
Oracle CorporationMySQL Server5.7.26 and prior, 8.0.16 and prior
Oracle CorporationMySQL Server*, 5.7.26 and prior, 8.0.16 and prior

Timeline

  • Jul 23, 2019 CVE Published
  • Oct 1, 2024 CVE Updated

References

  • x_refsource_MISC
  • USN-4070-1 vendor-advisoryx_refsource_UBUNTU
  • x_refsource_CONFIRM
  • x_refsource_CONFIRM
Open in Interactive Console →
$ Console Community · 100/wk Open console ›