Impact
A flaw in the Optimizer component of Oracle’s MySQL Server and MySQL Cluster allows an attacker with high‑privileged credentials who can reach the database over network protocols to trigger a hang or repeatable crash, wholly disrupting availability. The vulnerability does not compromise data confidentiality or integrity; it purely causes a denial of service.
Affected Systems
The vulnerability affects Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. All installations of these product lines running an affected version and exposed to the network are at risk.
Risk and Exploitability
The CVSS base score of 4.4 highlights a moderate availability impact. EPSS indicates an exploitation probability of less than 1%, suggesting very low prevalence in the wild. The vulnerability is not listed in CISA’s KEV catalog. The attack requires network access to the database and high‑privileged credentials; without such preconditions, the likelihood of successful exploitation remains limited.
OpenCVE Enrichment