PT-2019-1864 · Oracle+1 · Mysql Connector/J+1

Published

2019-04-16

·

Updated

2022-11-11

·

CVE-2019-2692

CVSS v3.1

6.3

Medium

VectorAV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle MySQL Connector/J versions prior to 8.0.15 Oracle MySQL Connector/J version 8.0.15
Description The issue is related to inadequate access control in the Connector/J subcomponent of Oracle MySQL Connectors, allowing a highly privileged attacker with logon access to the infrastructure where MySQL Connectors executes to potentially compromise MySQL Connectors. The exploitation of this issue is difficult and requires human interaction from a person other than the attacker. Successful attacks can result in the takeover of MySQL Connectors.
Recommendations For Oracle MySQL Connector/J versions prior to 8.0.15, update to a version later than 8.0.15 to resolve the issue. For Oracle MySQL Connector/J version 8.0.15, update to a version later than 8.0.15 to resolve the issue. As a temporary workaround, consider restricting access to the Connector/J subcomponent until a patch is available.

Fix

Improper Access Control

Type Confusion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2020-2983
BDU:2019-01516
CVE-2019-2692
GHSA-JCQ3-CPRP-M333
OESA-2022-1547
OESA-2022-2076

Affected Products

Alt Linux
Mysql Connector/J