CVE-2021-2471
published 2021-10-20CVE-2021-2471: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to…
PriorityP334medium5.9CVSS 3.1
AVNACHPRHUINSUCHINAH
EPSS
7.32%
93.7th percentile
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | cm1_mysql_8.0.27-1_on_cbl_mariner_1.0 | — | — |
| oracle | communications_cloud_native_core_console | — | — |
| oracle | communications_cloud_native_core_network_slice_selection_function | — | — |
| oracle | communications_cloud_native_core_policy | — | — |
| oracle | communications_cloud_native_core_security_edge_protection_proxy | — | — |
| oracle | mysql_connectors | 8.0.0 – 8.0.26 | — |
| oracle_corporation | mysql_connectors | — | — |
| quarkus | quarkus | < 2.2.4 | 2.2.4 |
| quarkus | quarkus | >= 2.3.0 < 2.6.0 | 2.6.0 |
Detection & IOCsextracted from sources · hover to see the quote
- →MySQL Connector/J contains an XML External Entity (XXE) vulnerability due to missing security checks when external general entities are included in XML sources ↗
- →Affected component is MySQL Connector/J (mysql-connector-java) versions 8.0.26 and prior; monitor for XXE-based exploitation attempts against MySQL Connector/J integrations ↗
- →Successful exploitation can result in unauthorized data access or complete DOS (hang/crash) of MySQL Connectors; monitor for unexpected crashes or data exfiltration from Connector/J-based applications ↗
- ·Exploitation requires high privileges and network access; attack complexity is rated High (AC:H), limiting opportunistic exploitation ↗
- ·In OpenShift Container Platform, the affected Presto/Metering component is deprecated since OCP 4.6 and removed from OCP 4.9+; affected deployments are marked wontfix ↗
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H
nvdv2.07.9HIGHAV:N/AC:M/Au:S/C:C/I:N/A:C
osv5.9MEDIUM
vendor_msrc5.9MEDIUM
vendor_oracle5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Communications Risk Matrix: CNC Console (MySQL Connectors) — CVE-2021-2471
vendor_oracle·2022-04-15·CVSS 5.9
CVE-2021-2471 [MEDIUM] Oracle Oracle Communications Risk Matrix: CNC Console (MySQL Connectors) — CVE-2021-2471
Oracle Oracle Communications Risk Matrix: CNC Console (MySQL Connectors) vulnerability
CVE: CVE-2021-2471
CVSS: 5.9
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Red Hat
mysql-connector-java: unauthorized access to critical
vendor_redhat·2021-10-20·CVSS 5.9
CVE-2021-2471 [MEDIUM] CWE-863 mysql-connector-java: unauthorized access to critical
mysql-connector-java: unauthorized access to critical
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
MySQL Connector/J has no security check when external general entit
Oracle
Oracle Oracle MySQL Risk Matrix: Connector/J — CVE-2021-2471
vendor_oracle·2021-10-15·CVSS 5.9
CVE-2021-2471 [MEDIUM] Oracle Oracle MySQL Risk Matrix: Connector/J — CVE-2021-2471
Oracle Oracle MySQL Risk Matrix: Connector/J vulnerability
CVE: CVE-2021-2471
CVSS: 5.9
Protocol: MySQL Protocol
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Microsoft
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privil
vendor_msrc·2021-10-12·CVSS 5.9
CVE-2021-2471 [MEDIUM] Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privil
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affecte
OSV
Incorrect Authorization in MySQL Connector Java
osv·2022-05-24
CVE-2021-2471 [MEDIUM] Incorrect Authorization in MySQL Connector Java
Incorrect Authorization in MySQL Connector Java
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
GHSA
Incorrect Authorization in MySQL Connector Java
ghsa·2022-05-24
CVE-2021-2471 [MEDIUM] CWE-863 Incorrect Authorization in MySQL Connector Java
Incorrect Authorization in MySQL Connector Java
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
OSV
CVE-2021-2471: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)
osv·2021-10-20·CVSS 5.9
CVE-2021-2471 [MEDIUM] CVE-2021-2471: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
No detection rules found.
No public exploits indexed.
2021-10-20
Published