Impact
The flaw resides in the Optimizer component of MySQL Server and MySQL Cluster. A high‑privileged attacker with network access can exploit unvalidated input to cause the optimizer to hang or terminate, leading to a full denial of service. The weakness is a resource‑exhaustion type (CWE‑400) that degrades availability without affecting confidentiality or integrity.
Affected Systems
Oracle MySQL Server and Oracle MySQL Cluster, versions 9.7.0 through 9.7.1, are affected. The issue applies only to these releases and any installation that allows the database to be reached over network protocols such as the native MySQL protocol.
Risk and Exploitability
The CVSS 3.1 Base Score of 4.9 indicates a moderate risk driven by availability impact. With an EPSS score of less than 1 % the likelihood of exploitation is considered low, and the vulnerability is not listed in the CISA KEV catalog. Attackers must possess high‑privilege credentials and network access, making the threat most potent against exposed or poorly secured MySQL instances.
OpenCVE Enrichment