« List of all CVEs

CVE-2019-2923

Published: 10/16/2019 Last updated: 10/15/2024 Reserved: 12/14/2018

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Encryption). Supported versions that are affected are 5.6.45 and prior and 5.7.27 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.0 Base Score 5.3 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N).

CNA assigner: oracle (43595867-4340-4103-b7a2-9a5208d29a85) Requested by: n/a

Opam packages affected (1)

conf-mysql

Products affected (2)

Product Vendor Version
MySQL Server Oracle Corporation < ef0394ca25953ea0eddcc82feae1f750451f1876
MySQL Server Oracle Corporation < f6205f8215f12a96518ac9469ff76294ae7bd612

References (12)