QID 20316

Date Published: 2023-01-18

QID 20316: Oracle MySQL January 2023 Critical Patch Update (CPUJAN2023)

This Critical Patch Update contains 37 new security patches for Oracle MySQL.

Affected Versions:
MySQL Server, versions 5.7.40 and prior, 8.0.31 and prior.

QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of MySQL via the banner exposed by the service.

QID Detection Logic (Authenticated):
This QID detects vulnerable versions of MySQL

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Medium - 4.4 severity.
  • Solution
    Refer to vendor advisory Oracle MySQL January 2023 .
    Software Advisories
    Advisory ID Software Component Link
    CPUJAN2023 URL Logo www.oracle.com/security-alerts/cpujan2023.html#AppendixMSQL