---
id: CVE-2025-30706
title: >-
  Vulnerability in the MySQL Connectors product of Oracle MySQL (component:
  Connector/J)
summary: >-
  Vulnerability in the MySQL Connectors product of Oracle MySQL (component:
  Connector/J).  Supported versions that are affected are 9.0.0-9.2.0. Difficult
  to exploit vulnerability allows low privileged attacker with network access
  via mult…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-276
vendor: oracle
product: mysql_connector/j
affected:
  - 'mysql_connector/j >= 9.0.0, <= 9.2.0'
published: '2025-04-15'
updated: '2026-09-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-30706'
references:
  - url: 'https://www.oracle.com/security-alerts/cpuapr2025.html'
    label: secalert_us@oracle.com
  - url: 'https://security.netapp.com/advisory/ntap-20250418-0007/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.00614
epssPercentile: 0.47175
ingestedAt: '2026-09-03T19:07:23.596Z'
---

## Overview

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/J).  Supported versions that are affected are 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Connectors.  Successful attacks of this vulnerability can result in takeover of MySQL Connectors. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).

## Affected

- `mysql_connector/j >= 9.0.0, <= 9.2.0`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
