QID 378430

Date Published: 2023-04-19

QID 378430: Oracle MySQL Connectors 8.0.x Denial of Service (DoS) Vulnerability (CPUAPR2023)

MySQL Connectors provide connectivity to the MySQL server for client programs.

Affected Version:
MySQL Connector/ODBC 8.0.32 and prior
MySQL Connector/C++ 8.0.32 and prior
QID Detection Logic (Authenticated):
This QID checks for the file version of MySQL Connector

Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    MySQL has released Oracle MySQL Connector 8.0.33 to mitigate these vulnerabilities. Refer to advisory MySQL Connector 8.0.x

    Vendor References

    CVEs related to QID 378430

    Software Advisories
    Advisory ID Software Component Link
    MySQL Connector 8.0.x URL Logo www.oracle.com/security-alerts/cpuapr2023.html