Impact
The flaw in Oracle MySQL Router permits an unauthenticated attacker who can reach the router’s HTTP interface to create, delete, or modify data that passes through the router. This can lead to unauthorized access to confidential data and tampering with database contents, violating confidentiality and integrity. The weakness is a classic access-control failure and is identified as CWE-284.
Affected Systems
Oracle MySQL Router versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1 contain the vulnerability; earlier or later releases are not affected.
Risk and Exploitability
The CVSS v3.1 score of 7.4 places the flaw in the high‑severity category. An EPSS score of less than 1% indicates a historically low likelihood of exploitation, and the flaw has not been cataloged in CISA’s KEV. However, the attack path is simple: the attacker needs only network connectivity to the HTTP port, no authentication or special privileges, so any host that can reach the endpoint is vulnerable. Until the issue is corrected, unauthorized users can compromise data confidentiality and integrity through the router.
OpenCVE Enrichment