Impact
A vulnerability in Oracle MySQL Router (CWE-400) allows an unauthenticated attacker with network access over HTTP to trigger a crash that can be repeated to cause a complete denial of service. The flaw is easily exploitable and results in availability damage, with no impact on confidentiality or integrity.
Affected Systems
Oracle Corporation’s MySQL Router is impacted. Affected releases include 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 reflects a high availability impact. The EPSS score is below 1%, indicating a low probability of widespread exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack path is an unauthenticated HTTP request sent to the router, which is straightforward to construct and does not require privileged credentials.
OpenCVE Enrichment