CVE-2022-21457
Description
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Risk Information
Base Score
5.9
MODERATE
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS Score
Exploitation Probability
1.859
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities are affected in Mysql 8.0.28 | Windows |
| Multiple Vulnerabilities are affected in Netapp Active Iq Unified Manager 2.3 | Windows |
| Multiple Vulnerabilities are affected in Netapp Oncommand Insight 2.3 | Windows |
| Multiple Vulnerabilities are affected in Netapp Snapcenter 2.3 | Windows |
| MySQL database (USN-5400-1) mysql-server-5.7_5.7.38-0ubuntu0.18.04.1_i386.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-5.7_5.7.38-0ubuntu0.18.04.1_amd64.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-8.0_8.0.29-0ubuntu0.20.04.3_i386.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-8.0_8.0.29-0ubuntu0.20.04.3_amd64.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-8.0_8.0.29-0ubuntu0.21.10.2_i386.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-8.0_8.0.29-0ubuntu0.21.10.2_amd64.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-8.0_8.0.29-0ubuntu0.22.04.2_i386.deb | Linux |
| MySQL database (USN-5400-1) mysql-server-8.0_8.0.29-0ubuntu0.22.04.2_amd64.deb | Linux |
| Mysql update (ELSA-2022-6590) mysql-8.0.30-3.el9_0.x86_64.rpm | Linux |
| Mysql-common update (ELSA-2022-6590) mysql-common-8.0.30-3.el9_0.x86_64.rpm | Linux |
| Mysql-errmsg update (ELSA-2022-6590) mysql-errmsg-8.0.30-3.el9_0.x86_64.rpm | Linux |
| Mysql-server update (ELSA-2022-6590) mysql-server-8.0.30-3.el9_0.x86_64.rpm | Linux |
| (RHSA-2022:6590) mysql security, bug fix, and enhancement update mysql-8.0.30-3.el9_0.x86_64.rpm | Linux |
| (RHSA-2022:6590) mysql security, bug fix, and enhancement update mysql-common-8.0.30-3.el9_0.x86_64.rpm | Linux |
| (RHSA-2022:6590) mysql security, bug fix, and enhancement update mysql-debugsource-8.0.30-3.el9_0.x86_64.rpm | Linux |
| (RHSA-2022:6590) mysql security, bug fix, and enhancement update mysql-errmsg-8.0.30-3.el9_0.x86_64.rpm | Linux |
| (RHSA-2022:6590) mysql security, bug fix, and enhancement update mysql-server-8.0.30-3.el9_0.x86_64.rpm | Linux |
| mysql security, bug fix, and enhancement update (RLSA-2022:6590) mysql-8.0.30-3.el9_0.x86_64.rpm | Linux |
| mysql security, bug fix, and enhancement update (RLSA-2022:6590) mysql-common-8.0.30-3.el9_0.x86_64.rpm | Linux |
| mysql security, bug fix, and enhancement update (RLSA-2022:6590) mysql-errmsg-8.0.30-3.el9_0.x86_64.rpm | Linux |
| mysql security, bug fix, and enhancement update (RLSA-2022:6590) mysql-server-8.0.30-3.el9_0.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mecab-0.996-2.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-libs-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-test-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-devel-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mecab-ipadic-2.7.0.20070801-16.module+el8.3.0+242+87d3366a.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-common-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-errmsg-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mysql-server-8.0.30-1.module+el8.6.0+1057+4d6a1721.x86_64.rpm | Linux |
| mysql:8.0 security, bug fix, and enhancement update (RLSA-2022:7119) mecab-ipadic-EUCJP-2.7.0.20070801-16.module+el8.3.0+242+87d3366a.x86_64.rpm | Linux |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234