Security readout for executives and security teams
Plain-English summary
CVE-2020-14760 affects Oracle MySQL Server 5.7.31 and earlier. A highly privileged attacker who can reach MySQL over the network could crash the server repeatedly or modify some accessible data. Business urgency is moderate: compromise requires elevated database privileges, but successful abuse can disrupt availability and damage data integrity.
Executive priority
Treat as a moderate-priority database maintenance and hardening issue. It is less urgent than unauthenticated remote code execution, but database outages and integrity loss can still create operational and reporting risk.
Technical view
The flaw is in MySQL Server’s Optimizer component. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H, score 5.5. Impact is limited to integrity and availability: unauthorized update, insert, or delete access to some accessible data, plus complete denial of service through hangs or repeatable crashes.
Likely exposure
Organizations running Oracle MySQL Server 5.7.31 or earlier are the stated exposure. Risk is concentrated where privileged database accounts can connect over network-accessible MySQL protocols.
Exploitation context
The source bundle does not show CISA KEV listing or cited evidence of active exploitation. The vulnerability is described as easily exploitable, but only by a high-privileged attacker with network access.
Researcher notes
Evidence is limited to the CVE description and vendor advisory references. No CWE is listed in the bundle. Do not assume affected versions beyond MySQL Server 5.7.31 and prior, and do not claim exploitation without additional cited evidence.
Mitigation direction
- Inventory MySQL Server versions and flag 5.7.31 or earlier.
- Follow Oracle CPU October 2020 guidance for applicable updates.
- Check NetApp or Gentoo advisories if those distributions or products are in scope.
- Restrict network access to MySQL services to trusted systems.
- Review and reduce high-privilege database accounts where possible.
Validation and detection
- Confirm each MySQL instance version against the affected 5.7.31-and-prior range.
- Verify vendor security updates are applied through Oracle or downstream package advisories.
- Review privileged accounts allowed to connect over network protocols.
- Check database logs for unexplained crashes, hangs, or unauthorized data changes.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-14760 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H1.24.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.5MediumVector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuoct2020.htmlCVE reference · x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20201023-0003/CVE reference · x_refsource_CONFIRM
- GLSA-202105-27CVE reference · vendor-advisory, x_refsource_GENTOO
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
