CVE-2021-2471
MEDIUMOracle MySQL Connector/J <8.0.26 - Privilege Escalation
Title source: llmDescription
Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 8.0.26 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Connectors accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 5.9 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H).
Exploits (4)
nomisec
WORKING POC
54 stars
by SecCoder-Security-Lab · poc
https://github.com/SecCoder-Security-Lab/jdbc-sqlxml-xxe
github
WORKING POC
5 stars
by JAckLosingHeart · javapoc
https://github.com/JAckLosingHeart/CVE-PoC-Collection/tree/main/mysql-CVE-2021-2471
Scores
CVSS v3
5.9
EPSS
0.6382
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:H
Details
Status
published
Products (7)
mysql/mysql-connector-java
8.0.0 - 8.0.27Maven
oracle/communications_cloud_native_core_console
1.9.0
oracle/communications_cloud_native_core_network_slice_selection_function
1.8.0
oracle/communications_cloud_native_core_policy
1.15.0
oracle/communications_cloud_native_core_security_edge_protection_proxy
1.7.0
oracle/mysql_connectors
8.0.0 - 8.0.26
quarkus/quarkus
< 2.2.4
Published
Oct 20, 2021
Tracked Since
Feb 18, 2026