CVE-2022-21457

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: PAM Auth Plugin). Supported versions that are affected are 8.0.28 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.1 Base Score 5.9 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N).
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*

History

10 May 2022, 17:46

Type Values Removed Values Added
CPE cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:windows:*:*
cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
References (CONFIRM) https://security.netapp.com/advisory/ntap-20220429-0005/ - (CONFIRM) https://security.netapp.com/advisory/ntap-20220429-0005/ - Third Party Advisory
First Time Netapp
Netapp active Iq Unified Manager
Netapp oncommand Insight
Netapp snapcenter

29 Apr 2022, 14:15

Type Values Removed Values Added
References
  • (CONFIRM) https://security.netapp.com/advisory/ntap-20220429-0005/ -

27 Apr 2022, 20:51

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : 5.9
v2 : 4.3
v3 : 5.9
References (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - (MISC) https://www.oracle.com/security-alerts/cpuapr2022.html - Vendor Advisory
First Time Oracle
Oracle mysql Server
CWE NVD-CWE-noinfo

19 Apr 2022, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-04-19 21:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-21457

Mitre link : CVE-2022-21457

CVE.ORG link : CVE-2022-21457


JSON object : View

Products Affected

netapp

  • snapcenter
  • active_iq_unified_manager
  • oncommand_insight

oracle

  • mysql_server