CVE-2025-30706

Executive Summary

CVE-2025-30706 exposes a vulnerability in Oracle MySQL Connector/J (9.0.0‑9.2.0). A low‑privileged attacker with network access can exploit the flaw via multiple protocols, potentially taking full control of the connector. The issue carries a CVSS v3.1 score of 7.5, indicating high confidentiality, integrity, and availability impact. No current CISA KEV listing.


Authoritative CVE Metadata - CVSS Base Score: 7.5 (HIGH) - Published: 2025-04-15T21:16:00.043 - Last Modified: 2026-09-03T18:52:44.433

Original Description: Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J). Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors. Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

"To study and not think is a waste. To think and not study is dangerous."

— Confucius
Source: NVD