QID 20369

Date Published: 2023-11-23

QID 20369: Oracle MySQL OCT 2023 Critical Patch Update (CPUOCT2023)

This Critical Patch Update contains patches for 5.7.x, 8.0.x and 8.x.y oracle MySQL server

Affected Versions:
MySQL Server, versions 5.7.43 and prior
MySQL Server, versions 8.0.34 and prior.

MySQL Server, prior to 8.2.0

QID Detection Logic (Unauthenticated):
This QID detects vulnerable versions of MySQL via the banner exposed by the service.

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.6 severity.
  • Solution
    Refer to vendor advisory Oracle MySQL OCT 2023 .
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    cpuoct2023 URL Logo www.oracle.com/security-alerts/cpuoct2023.html