Impact
A flaw in the optimizer component of Oracle MySQL Server allows a low‑privileged attacker who can reach the server over the network to trigger a hang or repeatable crash, causing a denial of service. The weakness results in the server becoming unresponsive, which directly impacts availability while leaving confidentiality and integrity unaltered.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 contain the vulnerable optimizer component.
Risk and Exploitability
The vulnerability has a moderate CVSS v3.1 base score of 6.5, indicating a meaningful availability impact. Exploitation is feasible over the network using multiple protocols and requires only low privileged access with no user interaction. No exploitation data is publicly documented, the EPSS score is not available, and the flaw is not listed in CISA’s KEV catalog, suggesting that public attacks have not yet been observed.
OpenCVE Enrichment