PT-2020-2571 · Oracle+2 · Mysql Connectors+2

Bui Quang

·

Published

2019-05-25

·

Updated

2022-06-30

·

CVE-2020-2933

CVSS v2.0

3.5

Low

VectorAV:N/AC:M/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions MySQL Connectors versions 5.1.48 and prior
Description The issue is related to insufficient access control in the Connector/J component of Oracle MySQL's MySQL Connectors product. It allows a highly privileged attacker with network access via multiple protocols to compromise MySQL Connectors, resulting in a partial denial of service (DOS) of MySQL Connectors. The exploitation of this issue is considered difficult.
Recommendations For versions 5.1.48 and prior, update to a version that addresses the insufficient access control issue in the Connector/J component to prevent potential denial of service attacks. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2019-1915
BDU:2020-02605
CVE-2020-2933
DLA-2245-1
DSA-4703-1
OPENSUSE-SU-2021:1126-1
OPENSUSE-SU-2021:2622-1
OPENSUSE-SU-2021_1126-1
OPENSUSE-SU-2021_2622-1
SUSE-SU-2021:2877-1

Affected Products

Alt Linux
Mysql Connectors
Suse