# Percona Mysql is not tagged as impacted by Oracle Mysql Vulnerabilities

**URL:** <https://forums.percona.com/t/percona-mysql-is-not-tagged-as-impacted-by-oracle-mysql-vulnerabilities/12538>\
**Category:** MySQL & MariaDB\
**Tags:** closed-no-reply\
**Created:** [October 12, 2021, 9:46am UTC](https://forums.percona.com/t/percona-mysql-is-not-tagged-as-impacted-by-oracle-mysql-vulnerabilities/12538 "2021-10-12T09:46:39Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![boniarco](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.percona.com/boniarco/32/4641_2.png) [@boniarco](https://forums.percona.com/u/boniarco)\
**Post date:** [October 12, 2021, 9:46am UTC](https://forums.percona.com/t/percona-mysql-is-not-tagged-as-impacted-by-oracle-mysql-vulnerabilities/12538/1 "2021-10-12T09:46:39Z")

</div>

When a vulnerability is discovered in **Oracle Mysql** , for example you can take CVE-2021-2022, **Percona Mysql products are not tagged as impacted**.  
[https://nvd.nist.gov/vuln/detail/CVE-2021-2022](https://nvd.nist.gov/vuln/detail/CVE-2021-2022)  
While they are impacted as reported clearly here

> [@Does "CVE-2021-2022" vulnerability exist in Percona XtraDB v5.7.32?](https://forums.percona.com/t/does-cve-2021-2022-vulnerability-exist-in-percona-xtradb-v5-7-32/9534):
>
> Does “CVE-2021-2022” vulnerability exist in Percona XtraDB v5.7.32? If yes, do we have an ETA for the Security Patch release?

As result, the commercial vulnerability scanners do not report Percona Mysql installed versions as impacted and in need of an update. This is critical because many compliance schemas rely on Vulnerability Scanner reports as the source of truth (the same is for internal patching processes)

It is important to highlight that this is not true in the case of any **MariaDB vulnerability.**  
For any MariaDB vulnerability, **Percona server is tagged as impacted** as you can see in CVE-2021-27928

No idea why there is this difference, and if it is coherent with the code dependency in place.  
Any suggestion on how to enable commercial vulnerability scanners to discover Percona Mysql Products vulnerabilities?

Thanks  
Marco
