Impact
A flaw in the Optimizer component of Oracle MySQL Cluster allows an adversary with high privileges to trigger a system hang or crash, resulting in a complete denial of service. This vulnerability corresponds to CWE-400 (Uncontrolled Resource Consumption). The flaw is triggered by carefully crafted network traffic delivered through one or more supported protocols. Because the status of critical services is completely lost, system administrators must consider the service to be unavailable until a repair or recovery action is taken.
Affected Systems
Oracle MySQL Cluster versions from 8.0.0 to 8.0.47 are affected. The vulnerability exists in the server’s Optimizer module and was discovered in the bundled MySQL Cluster installation. Users running these versions should verify whether they are within the vulnerable range and plan an upgrade or patch accordingly.
Risk and Exploitability
The CVSS score of 4.9 indicates a moderate severity focused on availability. The EPSS score of less than 1% suggests few observed exploit attempts, and the vulnerability is not listed in CISA KEV. However, a remote attacker who can authenticate with high privileges can exploit the bug by sending malicious traffic over supported protocols, triggering the crash. The attack requires network access and privileged credentials but does not rely on social engineering or zero‑day code execution.
OpenCVE Enrichment