Back

HIGH

mysql-connector-java: Connector/J unspecified vulnerability (CPU October 2018)

Published Oct 17, 2018

Description

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 8.0.12 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.0 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).

Affected products

Remediation

Red Hat statement

Re Hat Satellite does not support using mysql as a back end database, thus the mysql connector is not used in any Satellite installation. The package mariadb Java client is now available in Red Hat Software Collections. It can be installed this way: ~~~ yum-config-manager --enable rhel-server-rhscl-7-rpms yum install rh-mariadb103-mariadb-java-client ~~~ This JDBC driver works fine with both, MariaDB and MySQL servers. We recommend use of mariadb-java-client over mysql-java-connector where possible.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner oracle
Published Oct 17, 2018
Updated Oct 2, 2024
Reserved Dec 15, 2017
CISA Vulnrichment
Updated Oct 2, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Oct 17, 2018
GHSA-4VRV-CH96-6H42