CVE-2019-2695 is a denial-of-service vulnerability affecting Oracle MySQL Server versions 8.0.15 and prior, specifically within the Optimizer subcomponent. A low-privileged attacker with network access can easily exploit this flaw to cause the MySQL Server to hang or repeatedly crash, leading to a complete denial of service. The vulnerability has a CVSS 3.0 Base Score of 6.5 (Medium), indicating a network-based attack with low attack complexity and low privileges required, resulting in high availability impact. There is no impact on confidentiality or integrity. Currently, there is no evidence of active exploitation, nor are there any public exploit modules available in Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0.0, <= 8.0.15CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
1.0CPE matchmatch criteria | cpe:2.3:a:redhat:software_collections:1.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:* | ||
8.1CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:8.1:*:*:*:*:*:*:* | ||
8.2CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux_eus:8.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.