Lucene search

K
nvd[email protected]NVD:CVE-2023-21963
HistoryApr 18, 2023 - 8:15 p.m.

CVE-2023-21963

2023-04-1820:15:16
web.nvd.nist.gov
1
oracle mysql server
vulnerability
network access
denial of service
cvss 3.1

2.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

2.8 Low

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.5%

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Connection Handling). Supported versions that are affected are 5.7.40 and prior and 8.0.31 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Server. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

Affected configurations

NVD
Node
oraclemysql_serverRange5.7.05.7.40
OR
oraclemysql_serverRange8.0.08.0.31

2.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

2.8 Low

AI Score

Confidence

High

0.0005 Low

EPSS

Percentile

17.5%