Impact
The defect exists in the Clone Plugin of Oracle MySQL Server and MySQL Cluster. It allows a high‑privileged attacker with network access through one or more protocols to force the server or cluster into a repeated crash or permanent hang, thereby denying legitimate users the ability to access the database service. The vulnerability has no impact on confidentiality or integrity, and it does not grant attacker access to data. The weakness can be classified as a resource exhaustion or state corruption flaw.
Affected Systems
Affected are Oracle MySQL Server versions 8.4.0‑8.4.10 and 9.7.0‑9.7.1, and Oracle MySQL Cluster versions 8.0.0‑8.0.47, 8.4.0‑8.4.10, and 9.7.0‑9.7.1. The vulnerability was reported for the Clone Plugin component, and only the identified versions are impacted – newer minor releases are absent from the affected range.
Risk and Exploitability
The CVSS score of 4.4 reflects a low‑to‑moderate severity with availability impact only. The EPSS score is less than 1%, indicating a very low likelihood of exploitation in the wild. Because the vulnerability requires a high‑privilege attacker with network access, exploitation opportunities may be limited to privileged insiders or compromised networks. The vulnerability is not yet listed in the CISA KEV catalog. Given the moderate score, the threat is considered permissible but a patch should be applied proactively to avoid potential disruptions.
OpenCVE Enrichment