Unrated severityNVD Advisory· Published Apr 29, 2010· Updated Apr 29, 2026
CVE-2009-4833
CVE-2009-4833
Description
MySQL Connector/NET before 6.0.4, when using encryption, does not verify SSL certificates during connection, which allows remote attackers to perform a man-in-the-middle attack with a spoofed SSL certificate.
Affected products
4cpe:2.3:a:oracle:mysql_connector\/net:*:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:oracle:mysql_connector\/net:*:*:*:*:*:*:*:*range: <=6.0.3
- cpe:2.3:a:oracle:mysql_connector\/net:6.0.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql_connector\/net:6.0.1:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:mysql_connector\/net:6.0.2:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- bugs.mysql.com/bug.phpnvdExploitPatch
- secunia.com/advisories/35604nvdVendor Advisory
- www.securityfocus.com/bid/35514nvd
- www.securitytracker.com/idnvd
- exchange.xforce.ibmcloud.com/vulnerabilities/51406nvd
News mentions
0No linked articles in our index yet.