CVE-2004-0835 describes a vulnerability in MySQL versions 3.x, 4.x, and 5.x where an ALTER TABLE RENAME operation incorrectly checks permissions against the original table instead of the target table. This flaw could allow unauthorized users to perform activities they shouldn't have access to. With a CVSS score of 7.5, it is considered highly severe, allowing network-based attacks with low complexity that can lead to partial compromise of confidentiality, integrity, and availability. While not on the KEV catalog, an ExploitDB entry exists, and the vulnerability has garnered significant community discussion, indicating potential awareness and exploitability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.1.0, <= 4.1.2CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.0.1CPE matchmatch criteria | cpe:2.3:a:mysql:mysql:*:*:*:*:*:*:*:* | ||
> 3.20, < 3.23.59CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 4.0.0, < 4.0.19CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
3.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:P/I:P/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.