Security restrictions bypass in MySQL Server - CVE-2019-2503

 

Security restrictions bypass in MySQL Server - CVE-2019-2503

Published: January 17, 2019


Vulnerability identifier: #VU17029
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-2503
CWE-ID: CWE-264
Exploitation vector: Adjecent network
Exploit availability: No public exploit available
Vendor: Oracle
Affected software:
MySQL Server

Detailed vulnerability description

The vulnerability allows an adjacent authenticated attacker to bypass security restrictions.

The weakness exists in MySQL Protocol due to unspecified flaw. An adjacent attacker can bypass security restrictions to read potentially sensitive information and cause the service to crash.

How to mitigate CVE-2019-2503

Install update from vendor's website.

Sources