CVE-2020-2934: Medium severity oracle mysql connector/j vulnerability
A flaw was found in the mysql-connector-java package. A complicated attack against the mysql Connector/J allows attackers on the local network to interfere with a user's connection and insert unauthorized SQL commands.
Other sources
An unspecified vulnerability in multiple Oracle products could allow an unauthenticated attacker to cause low confidentiality impact, low integrity impact, and low availability impact.
— IBM
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.14 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data
— Red Hat
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.19 and prior and 5.1.48 and prior. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of MySQL Connectors. CVSS 3.0 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:L).
Affected Software
Remediation
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2020-2934?
CVE-2020-2934 has been classified as a difficult to exploit vulnerability that affects certain versions of MySQL Connectors.
How do I fix CVE-2020-2934?
To mitigate the risk of CVE-2020-2934, upgrade to MySQL Connector/J version 8.0.20 or later if you are using versions 8.0.19 or earlier, or version 5.1.49 or later if using versions 5.1.48 or earlier.
What versions are affected by CVE-2020-2934?
CVE-2020-2934 affects MySQL Connector/J versions 8.0.19 and earlier, as well as 5.1.48 and earlier.
Can an unauthenticated attacker exploit CVE-2020-2934?
Yes, CVE-2020-2934 allows an unauthenticated attacker with network access to attempt to exploit the vulnerability.
What components are involved in CVE-2020-2934?
CVE-2020-2934 is related to the MySQL Connectors product under Oracle MySQL, specifically the Connector/J component.