Executive brief
Oracle MySQL Connector/J, a software component that allows Java applications to communicate with MySQL databases, contains a security vulnerability. An attacker with low-level access to the network could potentially view, modify, or delete sensitive data managed by the connector. Additionally, this flaw could be used to cause a partial service disruption, impacting the reliability of applications that rely on this database connection.
Technical details
A vulnerability in the Connector/J component of Oracle MySQL Connectors allows a low-privileged attacker with network access via multiple protocols to compromise the system. The vulnerability is classified as difficult to exploit (Attack Complexity: High). Successful exploitation can lead to unauthorized creation, deletion, or modification of critical data, as well as unauthorized access to all data accessible via the connector. It also allows for a partial denial of service (DoS). The issue affects supported versions 9.7.0 through 9.7.1 and was addressed in the July 2026 Oracle Critical Patch Update.
Affected products
- Oracle MySQL Connectors (Connector/J) 9.7.0 - 9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle
- 2026-07-21: advisory: NVD publication date