PT-2018-2144 · Mysql Server+1 · Mysql Connectors+1

Published

2018-10-16

·

Updated

2025-08-06

·

CVE-2018-3258

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 8.0.12 and prior
Description The issue is related to insufficient access control in the Connector/J subcomponent of the MySQL Connectors system. It allows a remote attacker to gain unauthorized access to protected data. The vulnerability can be easily exploited by a low-privileged attacker with network access via multiple protocols, potentially leading to a takeover of MySQL Connectors.
Recommendations For versions 8.0.12 and prior, update to a version that includes a fix for this issue to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-00097
CVE-2018-3258
GHSA-4VRV-CH96-6H42
RHSA-2020:4366

Affected Products

Mysql Connectors
Red Os