CVE-2023-21971

Published on: Not Yet Published

Last Modified on: 07/21/2023 07:21:00 PM UTC

CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H

Certain versions of Active Iq Unified Manager from Netapp contain the following vulnerability:

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.32 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data and unauthorized read access to a subset of MySQL Connectors accessible data. CVSS 3.1 Base Score 5.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:L/A:H).

  • CVE-2023-21971 has been assigned by URL Logo secaler[email protected] to track the vulnerability - currently rated as MEDIUM severity.
  • Affected Vendor/Software: URL Logo Oracle Corporation - MySQL Connectors version = 8.0.32 and prior

CVSS3 Score: 5.3 - MEDIUM

Attack
Vector
Attack
Complexity
Privileges
Required
User
Interaction
NETWORK HIGH HIGH REQUIRED
Scope Confidentiality
Impact
Integrity
Impact
Availability
Impact
UNCHANGED LOW LOW HIGH

CVE References

Description Tags Link
Oracle Critical Patch Update Advisory - April 2023 Vendor Advisory
www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpuapr2023.html
Oracle Critical Patch Update Advisory - July 2023 www.oracle.com
text/html
URL Logo MISC www.oracle.com/security-alerts/cpujul2023.html
April 2023 MySQL Server Vulnerabilities in NetApp Products | NetApp Product Security security.netapp.com
text/html
URL Logo MISC security.netapp.com/advisory/ntap-20230427-0007/
CVE-2023-21971 MySQL Connector/J Vulnerability in NetApp Products | NetApp Product Security security.netapp.com
text/html
URL Logo MISC security.netapp.com/advisory/ntap-20230427-0010/

Related QID Numbers

  • 691150 Free Berkeley Software Distribution (FreeBSD) Security Update for mysql (f504a8d2-e105-11ed-85f6-84a93843eb75)

Exploit/POC from Github

CVE-2023-21971 Connector/J RCE Analysis分析

Known Affected Configurations (CPE V2.3)

Type Vendor Product Version Update Edition Language
ApplicationNetappActive Iq Unified Manager-AllAllAll
ApplicationNetappActive Iq Unified Manager-AllAllAll
ApplicationNetappActive Iq Unified Manager-AllAllAll
ApplicationNetappOncommand Insight-AllAllAll
ApplicationNetappSnapcenter-AllAllAll
ApplicationOracleCommunications Cloud Native Core Binding Support Function22.4.0AllAllAll
ApplicationOracleCommunications Cloud Native Core Binding Support Function23.1.0AllAllAll
ApplicationOracleCommunications Cloud Native Core Policy22.4.0AllAllAll
ApplicationOracleCommunications Cloud Native Core Policy23.1.0AllAllAll
ApplicationOracleMysql ConnectorsAllAllAllAll
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:linux:*:*:
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*:
  • cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*:
  • cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*:
  • cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:22.4.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_cloud_native_core_binding_support_function:23.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_cloud_native_core_policy:22.4.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:communications_cloud_native_core_policy:23.1.0:*:*:*:*:*:*:*:
  • cpe:2.3:a:oracle:mysql_connectors:*:*:*:*:*:*:*:*:

Social Mentions

Source Title Posted (UTC)
Twitter Icon @CVEreport CVE-2023-21971 : Vulnerability in the MySQL Connectors product of Oracle MySQL component: Connector/J . Supported… twitter.com/i/web/status/1… 2023-04-18 20:25:48
© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report