QID 376363

Date Published: 2022-01-26

QID 376363: Oracle MYSQL Connector/ODBC Critical Patch Update (CPU) January 2022 (CPUJAN2022)

Oracle MySQL Connector/ODBC is a standardized database driver

OpenSSL is used by Oracle MySQL Connector. Oracle MySQL Connector has addressed the applicable CVEs.
Affected Version:
MySQL Connector/ODBC 8.0.27 and prior

Fixed Version:
MySQL Connector/ODBC 8.0.28 QID Detection Logic (Authenticated):
This QID checks for the file version of MySQL Connector/ODBC

Successful exploitation could allow an attacker to affect the confidentiality, integrity, and availability of data on the target system.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    MySQL has released Oracle MySQL Connector 8.0.28 to mitigate the vulnerability. Refer to advisory MySQL Connector ODBC

    Vendor References

    CVEs related to QID 376363

    Software Advisories
    Advisory ID Software Component Link
    My SQL Connector/ODBC URL Logo www.oracle.com/security-alerts/cpujan2022.html#AppendixMSQL