Impact
The vulnerability resides in the DML component of Oracle MySQL Server. A high privileged attacker with network access, using any of the supported database protocols, can form a request that causes the server to hang or terminate in a crash. The result is a loss of service for all users of the affected MySQL instance. No compromise of data or code execution is disclosed; the impact is purely an availability disruption.
Affected Systems
Oracle MySQL Server from versions 8.0.0 through 8.0.45, 8.4.0 through 8.4.8, and 9.0.0 through 9.6.0 are susceptible. The issue is present within the server component that processes data manipulation language statements. All installation instances of these releases should be verified.
Risk and Exploitability
The CVSS 3.1 base score of 4.9 indicates moderate severity with an availability focus. The EPSS score is not available, so the current exploit probability is unknown; however the requirement for network access and high privileges implies that the attack would be targeted rather than widespread. The vulnerability is not listed in CISA’s KEV catalog, reflecting that no known widespread exploitation has been observed.
OpenCVE Enrichment