Impact
A flaw in Oracle’s MySQL Connector/Net (versions 9.7.0–9.7.1) permits an unauthenticated attacker with network access to take full control of the connector. The vulnerability is classified as CWE-284 (Improper Access Control) and, if exploited, would allow the attacker to exfiltrate data, modify or delete data, and disrupt service availability, resulting in confidentiality, integrity, and availability impacts.
Affected Systems
Developers and administrators using Oracle MySQL Connector/Net 9.7.0 or 9.7.1 for .NET applications are affected. Any system that hosts or communicates with these connector binaries over the network is at risk.
Risk and Exploitability
The CVSS base score of 8.1 indicates high severity, while an EPSS score less than 1 % reflects a low probability of widespread exploitation at present. The connector is not listed in the CISA KEV catalog. Exploitation requires an unauthenticated network connection to an exposed Connector/Net endpoint, often through multiple protocols, and while the vulnerability is difficult to exploit, the potential impact is substantial. Network isolation, authentication enforcement, and diligent monitoring are recommended to mitigate the threat.
OpenCVE Enrichment