CVE-2019-2692
Published: 23 April 2019
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.15 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 6.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H).
Priority
Status
Package | Release | Status |
---|---|---|
mysql-connector-java Launchpad, Ubuntu, Debian |
bionic |
Not vulnerable
(affects 8.x only)
|
cosmic |
Ignored
(end of life)
|
|
disco |
Does not exist
|
|
trusty |
Not vulnerable
(affects 8.x only)
|
|
upstream |
Not vulnerable
(debian: Only affects 8.x)
|
|
xenial |
Not vulnerable
(affects 8.x only)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 6.3 |
Attack vector | Local |
Attack complexity | High |
Privileges required | High |
User interaction | Required |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.0/AV:L/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:H |