{"cvss":6.5,"datePublished":"2026-07-21T22:18:02.943","dateUpdated":"2026-09-03T18:33:57.200","description":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H).","id":"CVE-2026-60624","raw":{"affected":[{"affectedData":[{"product":"MySQL Connectors","vendor":"Oracle Corporation","versions":[{"lessThanOrEqual":"9.7.1","status":"affected","version":"9.7.0","versionType":"custom"}]}],"source":"secalert_us@oracle.com"}],"configurations":[{"nodes":[{"cpeMatch":[{"criteria":"cpe:2.3:a:oracle:mysql_connector\\/j:9.7.0:*:*:*:*:*:*:*","matchCriteriaId":"258C2F36-0196-4A62-AC4A-0959A858CA61","vulnerable":true},{"criteria":"cpe:2.3:a:oracle:mysql_connector\\/j:9.7.1:*:*:*:*:*:*:*","matchCriteriaId":"3209D81F-5180-4C28-97DF-39AEDE3C7FFA","vulnerable":true}],"negate":false,"operator":"OR"}]}],"cveTags":[],"descriptions":[{"lang":"en","value":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Connectors. CVSS 3.1 Base Score 6.5 (Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H)."}],"id":"CVE-2026-60624","lastModified":"2026-09-03T18:33:57.200","metrics":{"cvssMetricV31":[{"cvssData":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"HIGH","baseScore":6.5,"baseSeverity":"MEDIUM","confidentialityImpact":"NONE","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","version":"3.1"},"exploitabilityScore":2.8,"impactScore":3.6,"source":"secalert_us@oracle.com","type":"Secondary"}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"id":"CVE-2026-60624","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","timestamp":"2026-07-27T12:34:22.056806Z","version":"2.0.3"}}]},"published":"2026-07-21T22:18:02.943","references":[{"source":"secalert_us@oracle.com","tags":["Vendor Advisory"],"url":"https://www.oracle.com/security-alerts/cpujul2026.html"}],"sourceIdentifier":"secalert_us@oracle.com","vulnStatus":"Analyzed","weaknesses":[{"description":[{"lang":"en","value":"CWE-404"}],"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","type":"Secondary"}]},"severity":"MEDIUM","source":"nvd","title":"Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J)"}