Impact
Oracle MySQL’s Server and Cluster products contain a flaw in the Optimizer component that can allow a low‑privileged attacker with network access to force the database to hang or repeatedly crash, causing a denial of service. The vulnerability does not affect confidentiality or integrity, but it removes the availability of the MySQL service to authorized users.
Affected Systems
The affected products are Oracle MySQL Server and Oracle MySQL Cluster. Supported releases that are vulnerable are MySQL Server 9.7.0 to 9.7.1 and MySQL Cluster 9.7.0 to 9.7.1.
Risk and Exploitability
The CVSS 3.1 base score is 6.5, indicating moderate severity. The EPSS score of less than 1% suggests a low overall probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Nevertheless, the attack vector is network‑based, requiring only low privileges; an attacker who can reach the MySQL protocols can trigger the crash and permanently disrupt service.
OpenCVE Enrichment