Impact
The vulnerability resides in Oracle MySQL Connector/J versions 9.7.0 through 9.7.1. It allows a low‑privileged attacker with network reach to exploit the connector and gain unauthorized access to critical data or full access to all data accessible via the connector. The flaw is easily exploitable, with low complexity and no user interaction required, and it escalates the scope to affect related products.
Affected Systems
Oracle MySQL Connector/J, versions 9.7.0–9.7.1.
Risk and Exploitability
The CVSS v3.1 score is 7.7, indicating a high severity with significant confidentiality impact. The EPSS score is below 1%, suggesting a low probability of exploitation at the present time, and the vulnerability is not listed in CISA's KEV catalogue. Attackers can reach the target over the network with low effort and low privileges. The scope change means a successful attack could affect other components that rely on the connector. Given the moderate exploitation probability but high impact, the risk remains significant and should be addressed promptly.
OpenCVE Enrichment