8.0.33
19 years ago
1 years ago
Known vulnerabilities in the mysql:mysql-connector-java package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
mysql:mysql-connector-java is a provides connectivity for client applications developed in the Java programming language with MySQL Connector/J, a driver that implements the Java Database Connectivity (JDBC) API. Affected versions of this package are vulnerable to Improper Authorization via the How to fix Improper Authorization? Upgrade | [,8.0.28) |
mysql:mysql-connector-java is a provides connectivity for client applications developed in the Java programming language with MySQL Connector/J, a driver that implements the Java Database Connectivity (JDBC) API. Affected versions of this package are vulnerable to XML External Entity (XXE) Injection via the How to fix XML External Entity (XXE) Injection? Upgrade | [,8.0.27) |
mysql:mysql-connector-java provides connectivity for client applications developed in the Java programming language with MySQL Connector/J, a driver that implements the Java Database Connectivity (JDBC) API. Affected versions of this package are vulnerable to Access Control Bypass.
A vulnerability in the How to fix Access Control Bypass? Upgrade | [,8.0.13) |
mysql:mysql-connector-java provides connectivity for client applications developed in the Java programming language with MySQL Connector/J, a driver that implements the Java Database Connectivity (JDBC) API. Affected versions of this package are vulnerable to SQL Injection. Remote authenticated users may be allowed to read, update, insert or delete access to a subset of MySQL Connector accessible data. How to fix SQL Injection? Upgrade | [,5.1.35) |
mysql:mysql-connector-java provides connectivity for client applications developed in the Java programming language with MySQL Connector/J, a driver that implements the Java Database Connectivity (JDBC) API. Affected versions of this package are vulnerable to Privilege Escalation. A user with high privileges who is logged onto the infrastructure where MySQL Connectors executes to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. How to fix Privilege Escalation? Upgrade | [,8.0.16) |
Affected versions of the package are vulnerable to Arbitrary Code Execution. Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/J). Supported versions that are affected are 5.1.41 and earlier. Easily "exploitable" vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. While the vulnerability is in MySQL Connectors, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Connectors accessible data as well as unauthorized read access to a subset of MySQL Connectors accessible data. How to fix Arbitrary Code Execution? Upgrade | [,5.1.42) |
| [,5.1.41) |
Vulnerability in the MySQL Connectors component of Oracle MySQL ( | [,5.1.42) |