Impact
A low‑privileged attacker who can reach the database over the network can target the optimizer module in Oracle MySQL Server and MySQL Cluster to trigger a hang or a repeatedly reproducible crash, effectively denying service to legitimate users. The impact is limited to availability; confidentiality and integrity remain intact.
Affected Systems
Oracle MySQL Server versions 9.0.0 through 9.7.1 and Oracle MySQL Cluster versions 9.0.0 through 9.7.1 are vulnerable. The weakness resides in the server’s optimizer component.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. The attack vector is network‑based, requiring only low‑privileged access through any protocol that can communicate with the MySQL instance. Successful exploitation results in a denial of service that can be repeated consistently by an attacker with equivalent access.
OpenCVE Enrichment