CVE-2019-2692: Medium severity oracle mysql connector/j vulnerability
An unspecified vulnerability in Oracle MySQL related to the Connectors Connector/J component could allow an authenticated attacker to take control of the system.
Other sources
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors.
Reference: http://www.oracle.com/technetwork/security-advisory/cpuapr2019-5072813.html
— Red Hat
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2692?
CVE-2019-2692 is classified as a difficult to exploit vulnerability that affects high privileged attackers with access to the MySQL Connectors.
How do I fix CVE-2019-2692?
To fix CVE-2019-2692, upgrade the MySQL Connector/J to version 8.0.16 or later.
What versions are affected by CVE-2019-2692?
CVE-2019-2692 affects MySQL Connector/J version 8.0.15 and prior.
Who is impacted by CVE-2019-2692?
Only high privileged attackers who have logon access to the infrastructure where MySQL Connectors is executed are impacted by CVE-2019-2692.
What component does CVE-2019-2692 affect?
CVE-2019-2692 affects the MySQL Connectors component of Oracle MySQL, specifically the Connector/J subcomponent.