Impact
The vulnerability resides in the DML component of Oracle MySQL Server. A high privileged attacker with network access, using any of the supported database protocols, can craft a request that triggers the server to hang or crash. The result is a loss of service for all users of the affected MySQL instance, with no disclosure of data manipulation or code execution capabilities.
Affected Systems
Oracle MySQL Server versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are susceptible. The issue exists in the server module that processes data manipulation language statements. All installations of these releases should be checked.
Risk and Exploitability
The CVSS 3.1 base score of 4.9 indicates moderate severity focused on availability. The EPSS score is less than 1%, implying a low but nonzero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. Attacks require network access and elevated privileges, suggesting they would be targeted rather than widespread.
OpenCVE Enrichment