Oracle MySQL
cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*
- >= 8.0.0, <= 8.0.41
- >= 8.4.0, <= 8.4.4
- >= 9.0.0, <= 9.2.0
A vulnerability has been identified in the MySQL Server component of Oracle MySQL, specifically in versions 8.0.0 through 8.0.41, 8.4.0 through 8.4.4, and 9.0.0 through 9.2.0. This vulnerability allows a high-privileged attacker with network access to MySQL Server to cause a complete denial-of-service by hanging the server or causing a frequently repeatable crash. Additionally, the vulnerability permits unauthorized updates, inserts, or deletions of some data accessible to MySQL Server.
Exploitation of this vulnerability leads to a complete denial-of-service condition on the MySQL Server, causing it to hang or crash frequently. Furthermore, it allows unauthorized modifications to some of the data accessible by MySQL Server, including updates, inserts, or deletions.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.