Impact
The vulnerability lies within the Optimizer component of Oracle MySQL Server and MySQL Cluster. An attacker with low privileges and network access can exploit it to force the server or cluster to hang or crash, effectively denying availability to legitimate users. This flaw does not compromise confidentiality or integrity, but it allows an adversary to disrupt database services by repeatedly triggering a crash. The weakness can be classified as a resource exhaustion or denial‑of‑service flaw, which is consistent with the identified activity of halting the system.
Affected Systems
Oracle offers MySQL Server and MySQL Cluster products. Versions 9.7.0 through 9.7.1 of both products are vulnerable. No other supported releases are currently known to be affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a medium‑severe impact focused solely on availability. The EPSS score of less than 1% suggests that, at the time of analysis, exploitation is considered unlikely, and the vulnerability is not listed in the CISA KEV catalog. An adversary can still attempt to exploit the flaw by submitting crafted queries over the network via any of the supported protocols; the attack vector is remote and requires only low‑privilege access. The documented impact allows an attacker to reliably cause service interruption, which may be sufficient to meet malicious objectives such as service disruption or as a pivot for further attacks within an environment that relies on MySQL for critical operations.
OpenCVE Enrichment