Impact
The vulnerability is located in the Optimizer component of Oracle MySQL Server and permits a high privileged attacker with network access to cause the server to hang or repeatedly crash. The effect is a complete denial of service, impacting availability only.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are affected. These versions include all releases within those ranges for the MySQL Server product from Oracle.
Risk and Exploitability
The CVSS v3.1 Base Score is 4.9, indicating moderate severity with a purely availability impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is network-based via multiple protocols; an attacker must possess high privileges to trigger the crash. The ability to cause a full service halt raises the risk for systems exposed to potentially insecure networks, underscoring the importance of timely remediation.
OpenCVE Enrichment