Impact
This vulnerability resides in the Performance Schema component of Oracle MySQL Server and MySQL Cluster, enabling a high‑privileged attacker who has network access to read a subset of database tables that they should not be able to see, leading to a confidentiality impact. The issue stems from missing access control checks that expose internal metadata and data, aligning with information exposure weaknesses identified by CWE‑200 and improper authorization controls exemplified by CWE‑497.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected.
Risk and Exploitability
The CVSS base score of 2.7 reflects a low severity primarily affecting confidentiality. The EPSS score is below 1 % and the vulnerability is not listed in CISA KEV, indicating a limited likelihood of exploitation in the wild. Attackers must reach the MySQL instance over network protocols such as the MySQL client protocol or JDBC and possess high‑privileged credentials to exploit the missing controls.
OpenCVE Enrichment