Impact
The vulnerability exists in the Configurator component of Oracle MySQL Server and Oracle MySQL Cluster. It allows a low‑privileged user who has logged into the host machine to compromise the database instance, potentially gaining full control over data, configuration, and availability. The flaw is a manifestation of insufficient authorization controls (CWE-284) and an improper handling of configuration parameters (CWE-15). Successful exploitation would let an attacker read, modify, or delete data and maintain persistent access to the affected MySQL service.
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster versions 9.7.0 through 9.7.1 are affected. No other product versions are mentioned as vulnerable.
Risk and Exploitability
The flaw carries a CVSS 3.1 base score of 6.7, reflecting significant confidentiality, integrity, and availability impacts. Its EPSS score is below 1 %, indicating a low probability of zero‑day exploitation. The vulnerability is not listed in CISA’s KEV catalog and requires the attacker to have a local login on the system and an additional human interaction from a separate individual, such as an insider or compromised credential holder. While exploitation is non‑remote and requires human action, the potential for complete takeover makes it a high‑impact threat if achieved.
OpenCVE Enrichment