QID 20221

Date Published: 2021-04-21

QID 20221: Oracle MySQL April 2021 Critical Patch Update (CPUAPR2021)

This Critical Patch Update contains 49 new security patches for Oracle MySQL.

Affected Versions:
MySQL Server, versions 5.7.33 and prior, 8.0.23 and prior.

QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of MySQL via the banner exposed by the service.

(Authenticated):
This QID detects vulnerable versions of MySQL via mysql -V command

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to vendor advisory Oracle MySQL April 2021 .
    Software Advisories
    Advisory ID Software Component Link
    Oracle MySQL April 2021 Critical Patch Update (CPUAPR2021) URL Logo www.oracle.com/security-alerts/cpuapr2021.html#AppendixMSQL