VDB
CISA-2020-14828
CISA-2020-14828
PUBLISHED
CVSS 7.2 HIGH
Reported by oracle · Published October 21, 2020
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.21 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in takeover of MySQL Server. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Risk Scores
CVSS 3.1
7.2
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corporation | MySQL Server | 8.0.21 and prior |
| Oracle Corporation | MySQL Server | 8.0.21 and prior, 8.0.21 and prior |
Timeline
- Oct 21, 2020 CVE Published
- Sep 26, 2024 CVE Updated
- Apr 26, 2026 Security Advisory
References
- x_refsource_MISC
- x_refsource_CONFIRM
- GLSA-202105-27 vendor-advisoryx_refsource_GENTOO