Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.40 and earlier. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
CVSS Details
- CVSS 3.0 Base Score: 8.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Azul Zulu | — | Upgrade to Azul Zulu JDK 8 installer 8.21 (JDK 8u131, quarterly CPU) (LTS stream) | Apr 24, 2017 | Apr 24, 2017 |
| Debian | — | Upgrade mysql-connector-java | May 3, 2017 | Apr 24, 2017 |
| Huawei Euleros 2_0_sp2 | — | Upgrade mysql-connector-java | Feb 22, 2021 | Apr 24, 2017 |
| Huawei Euleros 2_0_sp3 | — | Upgrade mysql-connector-java | Jan 20, 2021 | Apr 24, 2017 |
| Huawei Euleros 2_0_sp5 | — | Upgrade mysql-connector-java | Feb 3, 2021 | Apr 24, 2017 |
| Huawei Euleros 2_0_sp8 | — | Upgrade mysql-connector-java | Jul 31, 2020 | Apr 24, 2017 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 21, 2017 |
| Suse | — | Upgrade mysql-connector-java | Sep 28, 2017 | Apr 24, 2017 |
| Ubuntu | — | No solution exists | Jun 26, 2025 | Apr 24, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub