Impact
A vulnerability in Oracle MySQL Connector/Net allows an unauthenticated attacker with network access to create, delete, or modify data without first authenticating. The flaw can lead to unauthorized access or complete control over all Connector/Net‑exposed data, directly compromising confidentiality and integrity. The condition for exploitation is difficult, yet bypasses all authentication safeguards.
Affected Systems
Oracle MySQL Connector/Net versions 9.7.0 through 9.7.1 are affected. Systems using these components, across any supported platform, are at risk if the Connector/Net library is present and reachable over the network.
Risk and Exploitability
The CVSS v3.1 score of 7.4 highlights significant impact to confidentiality and integrity, though availability is not affected. The EPSS score of less than 1% indicates very low but non‑zero exploitation probability, and the vulnerability is not listed in CISA KEV. The likely attack vector is network‑based, with no authentication required, making it a serious risk for exposed services. By exploiting the flaw an attacker can potentially gain unrestricted access to critical data managed by Connector/Net.
OpenCVE Enrichment