CVE-2009-4833

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
29/04/2010
Last modified:
11/04/2025

Description

MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:oracle:mysql_connector\/net:*:*:*:*:*:*:*:* 6.0.3 (including)
cpe:2.3:a:oracle:mysql_connector\/net:6.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_connector\/net:6.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:mysql_connector\/net:6.0.2:*:*:*:*:*:*:*