Impact
A flaw in the JSON Duality handling of the MySQL Server and MySQL Cluster components, identified as CWE-284 (Improper Access Control), allows an attacker with network access and high privilege to supply crafted input that causes the database service to hang or crash, resulting in a denial of service that impacts availability while leaving confidentiality and integrity unaffected.
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster are affected. The vulnerable releases are 9.7.0 through 9.7.1 for both server and cluster components.
Risk and Exploitability
The CVSS base score of 4.9 indicates moderate severity focused on availability. The EPSS score is below 1%, pointing to a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The attack requires an attacker with high privileges over a network connection using one of the supported protocols; the attack vector is inferred to be network-based because the exploit achieves the effect remotely.
OpenCVE Enrichment