CVE-2022-21363: Medium severity oracle mysql connectors vulnerability
An unspecified vulnerability in Oracle MySQL Connectors related to the Connector/J component could allow an authenticated attacker to take control of the system.
Other sources
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.27 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 6.6 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-21363.
What is the title of the vulnerability?
The title of the vulnerability is 'Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).'
What are the affected versions of MySQL Connectors?
The affected versions of MySQL Connectors are 8.0.27 and prior.
How can an attacker exploit this vulnerability?
The vulnerability allows a high privileged attacker with network access via multiple protocols to compromise MySQL Connectors.
What is the severity of CVE-2022-21363?
The severity of CVE-2022-21363 is medium with a CVSS score of 6.6.
Where can I find more information about CVE-2022-21363?
You can find more information about CVE-2022-21363 at the following references: [Reference 1](https://www.cve.org/CVERecord?id=CVE-2022-21363), [Reference 2](https://nvd.nist.gov/vuln/detail/CVE-2022-21363), [Reference 3](https://www.oracle.com/security-alerts/cpujan2022.html#AppendixMSQL), [Reference 4](https://bugzilla.redhat.com/show_bug.cgi?id=2047343), [Reference 5](https://access.redhat.com/errata/RHSA-2022:4623).
What is the Common Weakness Enumeration (CWE) ID for this vulnerability?
The Common Weakness Enumeration (CWE) ID for this vulnerability is CWE-280.