Impact
An exploitable flaw exists in the Server: JSON Duality and MySQL Cluster. The weakness allows high‑privileged attackers with network access to cause the database system to hang or crash repeatedly, resulting in a complete denial of service. The vulnerability is attributed to improper authorization (CWE‑284) and contributes to resource exhaustion. It has a CVSS 3.1 score of 4.9 and only affects availability.
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster are impacted when running versions 9.7.0, 9.7.1, or any intervening builds that include the JSON Duality component. These environments expose the database service over multiple network protocols and provide privileged credentials to attackers within the network.
Risk and Exploitability
The CVSS score indicates a moderate impact but the EPSS score is below 1 % and the vulnerability is not listed in CISA’s KEV catalog. Nonetheless, an attacker with high privileges and network reach can reliably trigger a crash, so the risk remains real for exposed systems. The attack vector is over the network and requires elevated privileges to send malicious JSON requests.
OpenCVE Enrichment