QID 20344

Date Published: 2023-04-19

QID 20344: Oracle MySQL April 2023 Critical Patch Update (CPUAPR2023)

This Critical Patch Update contains 26 new security patches for Oracle MySQL.

Affected Versions:
MySQL Server, versions 5.7.41 and prior, 8.0.32 and prior.

QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of MySQL via the banner exposed by the service.

QID Detection Logic (Authenticated):
This QID detects vulnerable versions of MySQL

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 6.8 severity.
  • Solution
    Refer to vendor advisory Oracle MySQL APRIL 2023 .
    Software Advisories
    Advisory ID Software Component Link
    MySQL CPUAPR2023 URL Logo www.oracle.com/security-alerts/cpuapr2023.html#AppendixMSQL