Impact
The flaw resides in Oracle MySQL Connector/C++ versions 9.7.0 through 9.7.1. An unauthenticated attacker who can reach the connector over the network can trigger a hang or repeatable crash, effectively rendering the connector unavailable. The impact is limited to availability, with no immediate breach of confidentiality or integrity.
Affected Systems
Oracle MySQL Connectors, specifically the Connector/C++ component versions 9.7.0 and 9.7.1.
Risk and Exploitability
The CVSS 3.1 base score of 7.5 indicates a high severity availability risk. The EPSS score of less than 1 percent suggests exploitation is unlikely but not impossible, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is network‑based, requiring no prior authentication, which means any host with network access to the connector could potentially enact the denial of service.
OpenCVE Enrichment