Impact
The vulnerability resides in the Clone Plugin component of Oracle MySQL Server and MySQL Cluster. A high‑privileged attacker with network access via multiple protocols can exploit the plugin to compromise the server, thereby gaining full control over the database instance. Successful exploitation results in disclosure and modification of all data, loss of availability, and complete administrative takeover, with high impacts on confidentiality, integrity, and availability as reflected in the CVSS score.
Affected Systems
Oracle Corporation products affected include MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. If one of these versions is installed, the system is vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 6.6 indicates moderate risk with high impact on confidentiality, integrity, and availability. The EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. An attacker would need network access and the ability to communicate over the supported protocols to reach the Clone Plugin. No local privilege escalation is described, so the threat is remote but requires a high‑privileged attacker with network access via multiple protocols.
OpenCVE Enrichment