CVE-2024-21060(netapp / active_iq_unified_manager)

LOWCVSS 4.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Data Dictionary). Supported versions that are affected are 8.0.36 and prior and 8.3.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).

1.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-770

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • mysql_server
  • oncommand_insight
  • oncommand_workflow_automation

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Affected systems

Products
active_iq_unified_managermysql_serveroncommand_insightoncommand_workflow_automationsnapcenter

1 version affected across 5 products

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-06: 110-06
Referenced assets1 URL
Full discourse1 post
  • Aviatrix Threat Research Center@aviatrixtrc

    ShinyHunters used URL-encoding techniques to bypass WAF protections and exploit CVE-2024-21060 in Oracle PeopleSoft, compromising FBI's job portal. The attackers moved laterally through the PeopleSoft environment to access employee databases. Runtime segmentation could have limited blast radius after initial compromise. #ThreatIntel 🔗 Read the full analysis: https://aviatrix.ai/threat-research-center/fbi-removes-accenture-contractor-after-patch-failure-led-to-shinyhunters-breach-2026

    0000082
    2.0K followersView on X
CPE platform detail6 entries

6 of 6 entries

PartVendorProductVersionTarget SWTarget HW
Appnetappactive_iq_unified_manager-vmware_vsphere-
Appnetappactive_iq_unified_manager-windows-
Appnetapponcommand_insight---
Appnetapponcommand_workflow_automation---
Appnetappsnapcenter---
Apporaclemysql_server---

Explore more