Impact
A vulnerability in Oracle MySQL Connector/J allows an unauthenticated attacker with network access, using several protocols, to gain unauthorized access to data stored in MySQL connectors. The issue requires human interaction from a person other than the attacker to complete the exploitation. If successful, the attacker can read critical data or obtain full access to all data that the connector manages. The weakness is an improper privilege management flaw that could expose sensitive information. The vulnerability encompasses multiple weaknesses, including missing authentication (CWE‑200), improper privilege management (CWE‑285), cross‑site request forgery (CWE‑352), and open redirect (CWE‑601).
Affected Systems
Oracle Corporation’s MySQL Connector/J component is affected. The vulnerability applies to supported versions 9.7.0 through 9.7.1, which are commonly used in Java applications that connect to MySQL databases.
Risk and Exploitability
The CVSS score is 6.5, indicating a medium severity impact, and the EPSS score is less than 1%, suggesting a very low probability of widespread exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers are likely to reach the vulnerable connector over a network that exposes the supported protocols, and while successful attacks require human interaction, the risk remains for organizations that run the affected version. The overall risk is moderate but does not warrant an emergency situation given the low EPSS, yet it should be addressed promptly to prevent data breach.
OpenCVE Enrichment