Impact
The vulnerability exists in the replication component of Oracle MySQL Server and MySQL Cluster. It allows an attacker who already has high privileges and network access through one of several protocols to successfully execute an exploit that will partially degrade service availability. The damage is limited to a partial denial of service; confidentiality and integrity are not affected. The CVSS vector reflects an accessible network location with high attack complexity and high privileges, resulting in a Base Score of 2.2.
Affected Systems
Affected products are Oracle Corporation MySQL Server and Oracle MySQL Cluster. Specifically, MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1. These versions are impacted by the replication flaw described in the CVE.
Risk and Exploitability
With a CVSS score of 2.2 the severity is low and the EPSS score is below 1 %, indicating a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to connect to the affected replication port or protocol and possess high privileged credentials, making the exploit difficult and confined to environments that expose replication traffic or where internal users have elevated privileges. Consequently, the risk is moderate but non‑zero for systems that expose replication services to have privileged users without strict segmentation.
OpenCVE Enrichment