#VU17029 Security restrictions bypass in MySQL Server - CVE-2019-2503

 

#VU17029 Security restrictions bypass in MySQL Server - CVE-2019-2503

Published: January 17, 2019


Vulnerability identifier: #VU17029
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-2503
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vulnerable software:
MySQL Server
Software vendor:
Oracle

Description

The vulnerability allows an adjacent authenticated attacker to bypass security restrictions.

The weakness exists in MySQL Protocol due to unspecified flaw. An adjacent attacker can bypass security restrictions to read potentially sensitive information and cause the service to crash.

Remediation

Install update from vendor's website.

External links