Impact
The vulnerability resides in Oracle MySQL Connector/J versions 9.7.0 and 9.7.1 and allows an attacker with low privileges but network access to create, delete, or modify data and to gain unauthorized read access to all data exposed by the connector. This can result in loss of confidentiality, integrity, and a partial denial of service. The weakness is a missing authentication check for a sensitive operation, classified as CWE‑306.
Affected Systems
Oracle MySQL Connector/J (Oracle Corporation) versions 9.7.0 and 9.7.1 on any platform that accepts network connections are vulnerable. All deployments of these releases that expose the Connector/J over the network are at risk, whereas later releases are presumed safe.
Risk and Exploitability
The CVSS v3.1 base score of 7.1 indicates high severity with substantial confidentiality, integrity, and availability impacts. The EPSS score below 1% suggests a low but nonzero likelihood of exploitation. The vulnerability is not listed in CISA KEV, indicating no widespread exploitation has been reported. An attacker would likely use a network-based exploit, sending crafted requests to the Connector/J over supported protocols, leveraging the low‑privilege authentication bypass to perform unauthorized operations or induce partial downtime.
OpenCVE Enrichment