Impact
The vulnerability in Oracle MySQL Connector/Net allows a low‑privileged attacker with network access to exploit the connector through multiple protocols, potentially taking full control of the Connector/Net process and all data it handles. Successful exploitation results in loss of confidentiality, integrity, and availability for data processed by the connector, and the scope change indicates that other dependent components could also be affected.
Affected Systems
Affected vendor: Oracle Corporation. Product: MySQL Connector/Net. Affected versions are 9.7.0 and 9.7.1. Because the vulnerability has a scope change, an attacker who compromises the connector can potentially affect additional products or components that rely on or interact with the connector. This means that other applications or services using the affected connector may also be at risk.
Risk and Exploitability
The CVSS vector AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H shows a network‑based attack with high complexity and low privilege. The EPSS score of <1% indicates a low current exploitation probability, and the vulnerability is not listed in CISA KEV. However, the scope change and potential for full takeover make this a high‑severity risk for deployments of the affected connector versions.
OpenCVE Enrichment