QID 20266

Date Published: 2022-07-20

QID 20266: Oracle MySQL July 2022 Critical Patch Update (CPUJUL2022)

This Critical Patch Update contains 23 new security patches for Oracle MySQL.

Affected Versions:
MySQL Server, versions 5.7.38 and prior, 8.0.29 and prior.

QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of MySQL via the banner exposed by the service.

QID Detection Logic (Authenticated):
This QID detects vulnerable versions of MySQL via mysql -V command

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Refer to vendor advisory Oracle MySQL July 2021 .
    Software Advisories
    Advisory ID Software Component Link
    CPUJUL2022 URL Logo www.oracle.com/security-alerts/cpujul2022.html#AppendixMSQL