CVE-2021-2471

MEDIUM

Oracle MySQL Connector/J <8.0.26 - Privilege Escalation

Title source: llm

Description

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).

Exploits (4)

nomisec WORKING POC 54 stars
by SecCoder-Security-Lab · poc
https://github.com/SecCoder-Security-Lab/jdbc-sqlxml-xxe
github WORKING POC 5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/mysql-CVE-2021-2471
nomisec WORKING POC 3 stars
by cckuailong · poc
https://github.com/cckuailong/CVE-2021-2471
nomisec WORKING POC 3 stars
by DrunkenShells · poc
https://github.com/DrunkenShells/CVE-2021-2471

Scores

CVSS v3 5.9
EPSS 0.6382
EPSS Percentile 98.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H

Details

Status published
Products (7)
mysql/mysql-connector-java 8.0.0 - 8.0.27Maven
oracle/communications_cloud_native_core_console 1.9.0
oracle/communications_cloud_native_core_network_slice_selection_function 1.8.0
oracle/communications_cloud_native_core_policy 1.15.0
oracle/communications_cloud_native_core_security_edge_protection_proxy 1.7.0
oracle/mysql_connectors 8.0.0 - 8.0.26
quarkus/quarkus < 2.2.4
Published Oct 20, 2021
Tracked Since Feb 18, 2026