MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:10
Type | Values Removed | Values Added |
---|---|---|
References | () http://bugs.mysql.com/bug.php?id=38700 - Exploit, Patch | |
References | () http://secunia.com/advisories/35604 - Vendor Advisory | |
References | () http://www.securityfocus.com/bid/35514 - | |
References | () http://www.securitytracker.com/id?1022482 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/51406 - |
Information
Published : 2010-04-29 19:30
Updated : 2025-04-11 00:51
NVD link : CVE-2009-4833
Mitre link : CVE-2009-4833
CVE.ORG link : CVE-2009-4833
JSON object : View
Products Affected
oracle
- mysql_connector\/net
CWE
CWE-20
Improper Input Validation