Impact
A vulnerability exists in Oracle MySQL Connector/J which allows an unauthenticated attacker who can reach the software over a network to trigger a hang or crash. The flaw exposes an availability impact: a successful exploitation can cause the connector to become unresponsive and repeatedly crash, effectively denying service to legitimate users. It is a classic denial‑of‑service weakness, with no confidentiality or integrity compromise.
Affected Systems
The flaw affects Oracle Corporation MySQL Connector/J versions 9.7.0 through 9.7.1. Users of these versions who are exposed to the network via the documented protocols are at risk.
Risk and Exploitability
The CVSS v3.1 score of 6.5 reflects a moderate severity with a high Availability impact, while the EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not present in the CISA KEV catalog and currently requires only network access – no credentials – to attempt an attack. The attacker would need to send a specially crafted request; however, the presence of a user interface interaction requirement suggests that a human trigger from another party is also needed to realize a complete denial.
OpenCVE Enrichment