{"id":"CVE-2015-2575","description":"Unspecified vulnerability in the MySQL Connectors component in Oracle MySQL 5.1.34 and earlier allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Connector/J.","cvssScore":4.9,"cvssVersion":"2.0","cvssVector":"AV:N/AC:M/Au:S/C:P/I:P/A:N","cvssMetrics":[{"version":"2.0","score":4.9,"vector":"AV:N/AC:M/Au:S/C:P/I:P/A:N","source":"nvd@nist.gov","sourceName":"NVD","type":"Primary"}],"cwes":["CWE-284"],"resolved":"NOT-APPLICABLE","published":"2015-04-16","lastModified":"2026-06-17","affectedProducts":[{"vendor":"debian","product":"debian linux","version":"8.0"},{"vendor":"suse","product":"linux enterprise desktop","version":"11","update":"sp3"},{"vendor":"suse","product":"linux enterprise server","version":"11","update":"sp3"},{"vendor":"suse","product":"linux enterprise software development kit","version":"11","update":"sp3"},{"vendor":"mysql","product":"mysql","versionEnd":"\u003c=5.1.34"}],"totalAffectedProducts":5,"references":[{"url":"https://security.netapp.com/advisory/ntap-20150417-0003","source":"osv","tags":["WEB"]},{"url":"http://lists.opensuse.org/opensuse-security-announce/2015-05/msg00026.html","source":"osv","tags":["WEB"]},{"url":"http://lists.opensuse.org/opensuse-updates/2015-05/msg00089.html","source":"osv","tags":["WEB"]},{"url":"http://www.debian.org/security/2016/dsa-3621","source":"osv","tags":["WEB"]},{"url":"http://www.oracle.com/technetwork/topics/security/cpuapr2015-2365600.html","source":"osv","tags":["WEB"]},{"url":"http://www.securityfocus.com/bid/74075","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"http://www.securitytracker.com/id/1032121","source":"secalert_us@oracle.com","tags":["Third Party Advisory","VDB Entry"]},{"url":"https://security.netapp.com/advisory/ntap-20150417-0003/","source":"secalert_us@oracle.com"}],"reasoning":{"decidingSource":"h2-history","decidingReason":"Historical classification excluded this CVE and no tracked product appears on the record, so it is not a Java problem ARMR was ever asked to address.","verdicts":[{"rule":"rejected","stage":"identity","outcome":"no-match"},{"rule":"armr-patch-file","stage":"scope","outcome":"no-match"},{"rule":"armr-secure-rule-file","stage":"scope","outcome":"no-match"},{"rule":"manual-classification","stage":"scope","outcome":"no-match"},{"rule":"h2-history","stage":"scope","outcome":"matched","status":"NOT-APPLICABLE","detail":"Found in legacy manual classifications","decisive":true}],"affectedPackages":[{"name":"mysql:mysql-connector-java","introduced":"0","fixed":"5.1.35"}]},"oracleAdvisories":[{"advisory":"Oracle Critical Patch Update April 2015","releaseType":"CPU","quarter":"2015-Q2","url":"https://www.oracle.com/security-alerts/cpuapr2015.html","products":[{"product":"Oracle MySQL","component":"Connector/J","affectedVersions":"5.1.34 and earlier"}]}],"assessment":{"record":{"state":"active"},"protection":{"level":"none"},"action":{"state":"not-needed","type":"none"},"review":{"state":"human","basis":"manual-review"}},"h2Comments":"## Manual Classification Context\n\n\n**Labels:** MYSQL PROTOCOL, CONNECTOR/J\n\n**Products:** MYSQL-CONNECTOR-JAVA, MYSQL CONNECTORS, ORACLE MYSQL","signals":{"hasPOC":false,"pocCount":0},"kev":{"inKEV":false},"epss":{"available":true,"score":0.03564,"percentile":0.8869},"ssvc":{"available":false}}