PT-2019-1864 · Oracle+1 · Mysql Connector/J+1
Published
2019-04-16
·
Updated
2022-11-11
·
CVE-2019-2692
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle MySQL Connector/J versions prior to 8.0.15
Oracle MySQL Connector/J version 8.0.15
Description
The issue is related to inadequate access control in the Connector/J subcomponent of Oracle MySQL Connectors, allowing a highly privileged attacker with logon access to the infrastructure where MySQL Connectors executes to potentially compromise MySQL Connectors. The exploitation of this issue is difficult and requires human interaction from a person other than the attacker. Successful attacks can result in the takeover of MySQL Connectors.
Recommendations
For Oracle MySQL Connector/J versions prior to 8.0.15, update to a version later than 8.0.15 to resolve the issue.
For Oracle MySQL Connector/J version 8.0.15, update to a version later than 8.0.15 to resolve the issue.
As a temporary workaround, consider restricting access to the Connector/J subcomponent until a patch is available.
Fix
Improper Access Control
Type Confusion
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Mysql Connector/J