Oracle MySQL Connectors C++ and ODBC (Apr 2024 CPU)

medium Nessus Plugin ID 193581

Synopsis

The remote host is affected by a vulnerability

Description

The versions of MySQL Connectors installed on the remote host prior to 8.4.0, are affected by a vulnerability as referenced in the April 2024 CPU advisory.

- Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/C++ (OpenSSL)). Supported versions that are affected are 8.3.0 and prior (64-bit) as well as 8.0.36 and prior (32-bit). Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data. (CVE-2023-6129)

- Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC (OpenSSL)). Supported versions that are affected are 8.3.0 and prior (64-bit) as well as 8.0.36 and prior (32-bit). Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors as well as unauthorized update, insert or delete access to some of MySQL Connectors accessible data. (CVE-2023-6129)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Apply the appropriate patch according to the April 2024 Oracle Critical Patch Update advisory.

See Also

https://www.oracle.com/docs/tech/security-alerts/cpuapr2024csaf.json

https://www.oracle.com/security-alerts/cpuapr2024.html

https://downloads.mysql.com/docs/connector-odbc-relnotes-en.a4.pdf

Plugin Details

Severity: Medium

ID: 193581

File Name: oracle_mysql_connectors_cpu_apr_2024.nasl

Version: 1.1

Type: local

Agent: windows, macosx, unix

Family: Misc.

Published: 4/19/2024

Updated: 10/15/2025

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 5.0

CVSS v2

Risk Factor: Medium

Base Score: 6.1

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:H/Au:N/C:N/I:P/A:C

CVSS Score Source: CVE-2023-6129

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.7

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

CPE: cpe:/a:oracle:mysql_connectors

Required KB Items: installed_sw/MySQL Connector

Exploit Ease: No known exploits are available

Patch Publication Date: 4/16/2024

Vulnerability Publication Date: 4/16/2024

Reference Information

CVE: CVE-2023-6129

IAVA: 2024-A-0240