QID 20273

Date Published: 2022-10-19

QID 20273: Oracle MySQL October 2022 Critical Patch Update (CPUOCT2022)

This Critical Patch Update contains 24 new security patches for Oracle MySQL.

Affected Versions:
MySQL Server, versions 5.7.39 and prior, 8.0.30 and prior.

QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of MySQL via the banner exposed by the service.

QID Detection Logic (Authenticated):
This QID detects vulnerable versions of MySQL

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Refer to vendor advisory Oracle MySQL October 2022 .
    Software Advisories
    Advisory ID Software Component Link
    CPUOCT2022 URL Logo www.oracle.com/security-alerts/cpuoct2022.html#AppendixMSQL