Broadcom API Gateway - MySQL Vulnerabilities CVE-2023-21972, CVE-2023-21976, CVE-2023-21977, CVE-2023-21980, CVE-2023-21982
search cancel

Broadcom API Gateway - MySQL Vulnerabilities CVE-2023-21972, CVE-2023-21976, CVE-2023-21977, CVE-2023-21980, CVE-2023-21982

book

Article ID: 266250

calendar_today

Updated On:

Products

CA API Gateway

Issue/Introduction

The following MySQL vulnerabilities have been found to affect MySQL 8.0.32 and prior

  • CVE-2023-21972
  • CVE-2023-21976
  • CVE-2023-21977
  • CVE-2023-21980
  • CVE-2023-21982

Environment

Broadcom API Gateway 10.1

Cause

CVE-2023-21972
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.32 and prior. 
Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. 
Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. 

CVE-2023-21976
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. 
Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. 
Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. 


CVE-2023-21977
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. 
Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. 
Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. 

CVE-2023-21980
Vulnerability in the MySQL Server product of Oracle MySQL (component: Client programs). Supported versions that are affected are 8.0.32 and prior. 
Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. 
Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Server. 

CVE-2023-21982 
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.32 and prior. 
Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. 
Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. 

Resolution

Within April's 2023 Gateway 10.1 Monthly Platform Update patch, we have included an upgrade to MySQL which brings it to version 8.0.33, free from the above vulnerabilities.

Hence please install Layer7_API_PlatformUpdate_64bit_v10.1-CentOS-2023-04-21.L7P available for download from Solutions and Patches web portal