Impact
A local unauthenticated attacker who can log on to the infrastructure where Oracle MySQL Server or MySQL Cluster runs can exploit a replication component flaw to force the database engine to crash or hang, resulting in a complete denial of service. The weakness exposes the server’s availability level, allowing repeated failures without impacting confidentiality or integrity.
Affected Systems
Oracle MySQL Server versions 8.4.0 through 8.4.10 and 9.7.0 through 9.7.1, and Oracle MySQL Cluster versions 8.0.0 through 8.0.47, 8.4.0 through 8.4.10, and 9.7.0 through 9.7.1 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 6.2 indicates moderate severity focused on availability (A:H). The EPSS score of <1% shows a very low probability of exploitation in the wild, and the vulnerability is not listed in CISA’s KEV catalog. Nevertheless, the flaw can be leveraged by any local user with infrastructure access, as the attack vector is inferred to be local. Successful exploitation results in repeated crashes or hangs that can disrupt services without requiring elevated permissions or network connectivity.
OpenCVE Enrichment