Executive brief
A vulnerability in Oracle's MySQL Connector/J, a software component used by Java applications to communicate with MySQL databases, can be exploited to cause a denial-of-service. An attacker can cause the application to hang or crash repeatedly, disrupting business operations and service availability. Exploitation requires a user other than the attacker to perform a specific action, such as clicking a link or interacting with a malicious site.
Technical details
A vulnerability in the Connector/J component of Oracle MySQL Connectors (versions 9.7.0 through 9.7.1) allows for a denial-of-service (DoS) attack. The flaw is easily exploitable by an unauthenticated attacker with network access via multiple protocols. The root cause is not explicitly detailed in the advisory but results in a hang or frequently repeatable crash of the connector. A key precondition for a successful attack is user interaction (UI:R) from a person other than the attacker. The impact is limited to the availability of the component (A:H), with no reported impact on confidentiality or integrity.
Affected products
- Oracle MySQL Connectors (Connector/J) 9.7.0 - 9.7.1
Timeline
- 2026-07-21: disclosed: Initial disclosure by Oracle in the July 2026 CPU
- 2026-07-21: advisory: NVD publication date