CVE-2022-21444
Published on: Not Yet Published
Last Modified on: 05/10/2022 05:46:00 PM UTC
Certain versions of Active Iq Unified Manager from Netapp contain the following vulnerability:
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DDL). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
- CVE-2022-21444 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Oracle Corporation - MySQL Server version = 5.7.37 and prior
- Affected Vendor/Software:
Oracle Corporation - MySQL Server version = 8.0.28 and prior
CVSS3 Score: 4.4 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | HIGH | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVSS2 Score: 2.1 - LOW
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | HIGH | SINGLE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
NONE | NONE | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update Advisory - April 2022 | www.oracle.com text/html |
![]() |
April 2022 MySQL Server Vulnerabilities in NetApp Products | NetApp Product Security | security.netapp.com text/html |
![]() |
Related QID Numbers
- 160112 Oracle Enterprise Linux Security Update for mysql (ELSA-2022-6590)
- 160186 Oracle Enterprise Linux Security Update for mysql:8.0 (ELSA-2022-7119)
- 198764 Ubuntu Security Notification for MySQL Vulnerabilities (USN-5400-1)
- 20256 Oracle MySQL April 2022 Critical Patch Update (CPUAPR2022)
- 240666 Red Hat Update for rh-mysql80-mysql security (RHSA-2022:6518)
- 240679 Red Hat Update for mysql security (RHSA-2022:6590)
- 240780 Red Hat Update for mysql:8.0 security (RHSA-2022:7119)
- 296082 Oracle Solaris 11.4 Support Repository Update (SRU) 48.126.1 Missing (CPUJUL2022)
- 900862 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (9539)
- 901052 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (9528)
- 901333 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (9539-1)
- 902380 Common Base Linux Mariner (CBL-Mariner) Security Update for mysql (9528-1)
- 940693 AlmaLinux Security Update for mysql (ALSA-2022:6590)
- 940710 AlmaLinux Security Update for mysql:8.0 (ALSA-2022:7119)
- 960208 Rocky Linux Security Update for mysql:8.0 (RLSA-2022:7119)
- 960476 Rocky Linux Security Update for mysql (RLSA-2022:6590)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Application | Netapp | Active Iq Unified Manager | - | All | All | All |
Application | Netapp | Oncommand Insight | - | All | All | All |
Application | Netapp | Snapcenter | - | All | All | All |
Application | Oracle | Mysql | All | All | All | All |
Application | Oracle | Mysql | All | All | All | All |
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*:
- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*:
- cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*:
- cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|