NA

CVE-2023-21971

Published: 18/04/2023 Updated: 21/07/2023
CVSS v3 Base Score: 5.3 | Impact Score: 4.7 | Exploitability Score: 0.5
VMScore: 0

Vulnerability Summary

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql connectors

oracle communications cloud native core policy 22.4.0

oracle communications cloud native core policy 23.1.0

oracle communications cloud native core binding support function 22.4.0

oracle communications cloud native core binding support function 23.1.0

netapp snapcenter -

netapp oncommand insight -

netapp active iq unified manager -

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J) Supported versions that are affected are 8032 and prior Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors ...

Github Repositories

CVE-2023-21971 Connector/J RCE Analysis分析

CVE-2023-21971 Connector/J RCE Analysis分析 参考 Remote Code Execution (RCE) in commysql:mysql-connector-j | CVE-2023-21971 | Snyk New Vulnerability in MySQL JDBC Driver: RCE and Unauthorized DB Access MYSQL JDBC反序列化解析 - 跳跳糖 (tttangcom) 漏洞概述 Oracle MySQL 的 MySQL Connectors 产品中的漏洞(组件:Connector/J)。受影响的受支持版