CVE-2020-2933: Low severity oracle mysql connector/j vulnerability
A flaw was found in the mysql-connector-java package. A complicated attack against the mysql Connector/J allows attackers on the local network to interfere with a user's connection, causing a denial of service of the MySQL Connectors.
Other sources
An unspecified vulnerability in Oracle MySQL related to the Connectors Connector/J component could allow an authenticated attacker to cause a denial of service resulting in a low availability impact using unknown attack vectors.
— IBM
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors.
References:
https://www.oracle.com/security-alerts/cpuapr2020.html https://lists.debian.org/debian-lts-announce/2020/06/msg00015.html https://www.debian.org/security/2020/dsa-4703
— Red Hat
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 5.1.48 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 2.2 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:L).
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2933?
CVE-2020-2933 is categorized as a difficult to exploit vulnerability that allows high privileged attackers with network access to compromise MySQL Connectors.
Which versions are affected by CVE-2020-2933?
CVE-2020-2933 affects MySQL Connector/J version 5.1.48 and prior.
How do I fix CVE-2020-2933?
To fix CVE-2020-2933, upgrade MySQL Connector/J to version 5.1.49 or later.
What types of network access does CVE-2020-2933 require for exploitation?
CVE-2020-2933 requires network access via multiple protocols to be exploited.
Who is affected by CVE-2020-2933?
CVE-2020-2933 affects users of MySQL Connectors, specifically those using the vulnerable versions.