Security readout for executives and security teams
Plain-English summary
This MySQL Server flaw can let an already high-privileged network user disrupt the database and modify some accessible data. The main business risk is service interruption, with limited data integrity impact. Sources identify affected supported versions as MySQL Server 8.0.26 and prior.
Executive priority
Treat as a moderate-priority database reliability and integrity issue. Prioritize systems running MySQL Server 8.0.26 or earlier, especially production databases with broad privileged access or weak network segmentation.
Technical view
CVE-2021-35612 affects Oracle MySQL Server's Server: Optimizer component. The CVSS 3.1 vector is AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H. Successful exploitation may cause hangs, repeatable crashes, and unauthorized update, insert, or delete access to some accessible data.
Likely exposure
Exposure is most relevant for MySQL Server 8.0.26 and prior where high-privileged accounts can connect over network protocols. The source data does not identify lower-privilege exploitation or specific exposed internet-facing scenarios.
Exploitation context
The CVE is not listed as KEV in the provided bundle, and no cited source states active exploitation. Exploitation requires high privileges but is described as easy once that access exists.
Researcher notes
The provided sources do not include root-cause detail, proof-of-concept status, or exact fixed build information. Analysis should stay anchored to Oracle CPU guidance, the CVSS vector, and affected-version statement.
Mitigation direction
- Inventory MySQL Server instances and identify versions 8.0.26 and prior.
- Review and apply Oracle's October 2021 Critical Patch Update guidance for MySQL Server.
- Check NetApp advisory guidance if MySQL is present through affected NetApp products.
- Restrict network access to MySQL to trusted administration and application paths.
- Review high-privileged database accounts and remove unnecessary access.
Validation and detection
- Confirm each MySQL Server version and patch level against Oracle CPU guidance.
- Verify high-privileged accounts are limited to required users and services.
- Review database logs for repeated crashes, hangs, or abnormal privileged data changes.
- Validate network controls block unnecessary MySQL protocol access.
- For NetApp environments, compare deployed products against the NetApp advisory.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2021-35612 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Medium
- CVSS
- 5.5 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H1.24.2Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
5.5MediumVector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
Source materials
- CVE List V5 sourceCVE List V5
- https://www.oracle.com/security-alerts/cpuoct2021.htmlCVE reference · x_refsource_MISC
- https://security.netapp.com/advisory/ntap-20211022-0003/CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
