Executive brief
A vulnerability exists in the Oracle MySQL Connector/J, a software component that allows Java applications to communicate with MySQL databases. An attacker with low-level access to the network could exploit this flaw to gain unauthorized access to sensitive data. This could lead to a significant breach of confidential information across the affected systems and potentially impact other integrated products.
Technical details
This vulnerability affects the Connector/J component of Oracle MySQL Connectors. It is classified as easily exploitable, requiring only low privileges and network access via multiple protocols. The exploit results in a scope change (S:C), meaning the impact can extend beyond the MySQL Connector itself to other products or the underlying environment. The primary impact is a high loss of confidentiality (C:H), potentially allowing an attacker to access all data reachable by the connector. The vulnerability was disclosed as part of the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle MySQL Connectors (Connector/J) 9.7.0 - 9.7.1
Timeline
- 2026-07-21: advisory: Published as part of Oracle Critical Patch Update
- 2026-07-21: disclosed