5.8
CVSSv2

CVE-2019-2435

Published: 16/01/2019 Updated: 24/08/2020
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.1 | Impact Score: 5.2 | Exploitability Score: 2.8
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:N

Vulnerability Summary

Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python). Supported versions that are affected are 8.0.13 and prior and 2.1.8 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all MySQL Connectors accessible data as well as unauthorized access to critical data or complete access to all MySQL Connectors accessible data. CVSS 3.0 Base Score 8.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

oracle mysql connectors

netapp active iq unified manager

netapp oncommand workflow automation -

netapp snapcenter -

Vendor Advisories

Debian Bug report logs - #919820 mysql-connector-python: CVE-2019-2435 Package: src:mysql-connector-python; Maintainer for src:mysql-connector-python is Sandro Tosi <morph@debianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 19 Jan 2019 21:42:02 UTC Severity: grave Tags: security, upstream F ...
Vulnerability in the MySQL Connectors component of Oracle MySQL (subcomponent: Connector/Python) Supported versions that are affected are 8013 and prior and 218 and prior Easily exploitable vulnerability allows unauthenticated attacker with network access via TLS to compromise MySQL Connectors Successful attacks require human interaction fro ...