First published: Wed Apr 15 2020(Updated: )
A flaw was found in the mysql-connector-java package. A complicated attack against the mysql Connector/J allows attackers on the local network to interfere with a user's connection and insert unauthorized SQL commands.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/mysql-connector-java | ||
redhat/mysql-connector-java | <8.0.15 | 8.0.15 |
redhat/mysql-connector-java | <5.1.49 | 5.1.49 |
Oracle MySQL connector\/j | <=5.1.48 | |
Oracle MySQL connector\/j | >=8.0.0<=8.0.19 | |
Fedora | =32 | |
Fedora | =33 | |
Debian | =8.0 | |
Debian | =9.0 | |
Oracle WebLogic Server | =12.1.3.0.0 | |
Oracle WebLogic Server | =12.2.1.3.0 | |
Oracle WebLogic Server | =12.2.1.4.0 | |
Oracle WebLogic Server | =14.1.1.0.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=3.0 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.2 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.1 | |
IBM Watson Query with Cloud Pak for Data as a Service | <=2.0 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.8 | |
IBM Data Virtualization on Cloud Pak for Data | <=1.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2020-2934 has been classified as a difficult to exploit vulnerability that affects certain versions of MySQL Connectors.
To mitigate the risk of CVE-2020-2934, upgrade to MySQL Connector/J version 8.0.20 or later if you are using versions 8.0.19 or earlier, or version 5.1.49 or later if using versions 5.1.48 or earlier.
CVE-2020-2934 affects MySQL Connector/J versions 8.0.19 and earlier, as well as 5.1.48 and earlier.
Yes, CVE-2020-2934 allows an unauthenticated attacker with network access to attempt to exploit the vulnerability.
CVE-2020-2934 is related to the MySQL Connectors product under Oracle MySQL, specifically the Connector/J component.