6.8
CVSSv2

CVE-2021-2021

Published: 20/01/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.8 | Impact Score: 6.9 | Exploitability Score: 8
CVSS v3 Base Score: 4.9 | Impact Score: 3.6 | Exploitability Score: 1.2
VMScore: 606
Vector: AV:N/AC:L/Au:S/C:N/I:N/A:C

Vulnerability Summary

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.22 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql

netapp snapcenter -

netapp oncommand workflow automation -

netapp oncommand insight -

fedoraproject fedora 32

fedoraproject fedora 33

Vendor Advisories

Debian Bug report logs - #980795 Security fixes from the January 2021 CPU Package: src:mysql-80; Maintainer for src:mysql-80 is Debian MySQL Maintainers <pkg-mysql-maint@listsaliothdebianorg>; Reported by: Lars Tangvald <larstangvald@oraclecom> Date: Fri, 22 Jan 2021 11:45:01 UTC Severity: grave Tags: fixed-up ...

Exploits

This Metasploit module exploits Java unsafe reflection and SSRF in the VMware vCenter Server Virtual SAN Health Check plugin's ProxygenController class to execute code as the vsphere-ui user See the vendor advisory for affected and patched versions Tested against VMware vCenter Server 67 Update 3m (Linux appliance ...