Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-21971


Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).


Published

2023-04-18T20:15:16.700

Last Modified

2024-11-21T07:44:01.233

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Primary
    NVD-CWE-noinfo

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application oracle communications_cloud_native_core_binding_support_function 22.4.0 Yes
Application oracle communications_cloud_native_core_binding_support_function 23.1.0 Yes
Application oracle communications_cloud_native_core_policy 22.4.0 Yes
Application oracle communications_cloud_native_core_policy 23.1.0 Yes
Application oracle mysql_connectors ≤ 8.0.32 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp active_iq_unified_manager - Yes
Application netapp oncommand_insight - Yes
Application netapp snapcenter - Yes

References