NFA servers may be flagged by security scans for vulnerabilities related to Oracle MySQL Server 8.4.x versions earlier than 8.4.10 (e.g., Plugin ID 321533, CVE-2026-46863, CVE-2026-60315).
search cancel

NFA servers may be flagged by security scans for vulnerabilities related to Oracle MySQL Server 8.4.x versions earlier than 8.4.10 (e.g., Plugin ID 321533, CVE-2026-46863, CVE-2026-60315).

book

Article ID: 447726

calendar_today

Updated On:

Products

Network Flow Analysis

Issue/Introduction

NFA servers may be flagged by security scans for vulnerabilities related to Oracle MySQL Server 8.4.x versions earlier than 8.4.10

Environment

  • Product: DX NetOps Network Flow Analysis (NFA)
  • Version: 25.4.9 and earlier
  • Component: MySQL Database

Cause

The current implementation of MySQL in NFA releases up to 25.4.9 uses versions that are subject to security advisories published in the June 2026 CPU.

Resolution

Broadcom Engineering is planning to remediate some of these vulnerabilities by upgrading the bundled MySQL version to 8.4.10.

  • Target Release: DX NetOps 25.4.11

Future release will be bundled with newer versions of MySQL to also address other vulnerabilities.

We recommend monitoring the release notes page:
https://techdocs.broadcom.com/us/en/ca-enterprise-software/it-operations-management/network-flow-analysis/25-4/release-notes.html 

Additional Information

Until the fix is available in a formal release, Broadcom recommends the following security hardening measures:

  1. Restrict Network Access: Ensure that MySQL standard ports (Default: 3308 for NFA) are protected by firewalls. Access should be restricted only to trusted Spectrum and Performance Management components.
  2. Least Privilege: Ensure the operating system user running the MySQL service only has permissions for the specific directories required for database operations.