Impact
The vulnerability resides in the MySQL Server and MySQL Cluster X Plugin. An unauthenticated attacker can send crafted requests over any of the protocols that the X Plugin listens on, leading to an application hang or a full crash and unauthorized read access to a limited set of data. This information exposure weakness (CWE‑200) and its availability impact allow the attacker to compromise the system without local privileges. The CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H) indicates a high‑severity remote attack.
Affected Systems
Affected Oracle MySQL products include MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, as well as MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1. These versions are listed as supported yet impacted, and the vulnerability requires only network connectivity to the compromised systems.
Risk and Exploitability
The CVSS score of 8.2 signals a high advisory severity that can impact confidentiality and availability. The EPSS score of less than 1 % indicates that exploitation probability is very low, and the vulnerability is not listed in the CISA KEV registry. Based on the description, it is inferred that the attacker can reach the X Plugin from any network interface, does not need to authenticate, and can trigger the failure by sending malicious payloads. Although the actual exploitation likelihood remains low, the potential impact is significant enough to warrant rapid remediation.
OpenCVE Enrichment