Impact
A vulnerability exists in Oracle's MySQL Connector/C++ that allows an unauthenticated attacker to perform unauthorized creation, deletion, or modification of critical data. The flaw also enables the attacker to access all data exposed by the MySQL Connector instances, compromising confidentiality and integrity of the information. The weakness is an authentication bypass, in which software incorrectly verifies or fails to verify credentials before granting data manipulation rights.
Affected Systems
Oracle Corporation MySQL Connectors, specifically Connector/C++. The affected versions are 9.7.0 through 9.7.1. Users running these releases are vulnerable; later releases are not impacted according to the supplied information.
Risk and Exploitability
The CVSS v3.1 score of 7.4 indicates high severity, and the EPSS score below 1% suggests that exploitation is unlikely at this time. The vulnerability is not listed in the CISA KEV catalog. Nevertheless, the attack vector is network-based and does not require user interaction, meaning remote attackers can exploit the flaw without local access. Successful exploitation results in full control over the data surfaces that the connector exposes, which can lead to significant operational or data breaches if the connector is used on critical infrastructure.
OpenCVE Enrichment