Impact
A flaw in the replication component of Oracle MySQL Server and MySQL Cluster permits an attacker who has high privilege and network access to the replication interfaces to cause the database to hang or crash repeatedly. The result is a full availability outage of the affected instance. The description does not mention any impact on confidentiality or integrity, and this lack of confidentiality or integrity impact is inferred from the text.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected. These releases are listed as supported and are impacted by the advisory.
Risk and Exploitability
The CVSS 3.1 base score of 4.4 reflects a medium severity impact limited to availability, and this availability-only impact is inferred from both the CVSS vector and the description. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild. The vulnerability is not yet included in the CISA KEV catalog, suggesting no documented active exploits at this time. Exploitation requires an attacker who can authenticate with high privileges on the replication interfaces and has network connectivity to the target database.
OpenCVE Enrichment