Impact
A defect in the Optimizer component of Oracle MySQL Server and MySQL Cluster enables a high privileged attacker who can communicate over the network through any of the supported protocols to cause the database services to hang or crash repeatedly. The result is a complete loss of availability, with no disclosed impact to confidentiality or integrity.
Affected Systems
Affected are Oracle MySQL Server and MySQL Cluster versions 9.7.0 through 9.7.1. These releases are vulnerable to the described optimizer flaw.
Risk and Exploitability
The CVSS v3.1 Base Score of 4.9 highlights a moderate availability impact. The EPSS score of less than 1% indicates a very low likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The likely attack path requires the attacker to have high privilege credentials on the host, access to the network interfaces exposing MySQL, and to submit a query that triggers the optimizer bug. Successful exploitation results in a service crash that is repeatable until the system is restarted or patched.
OpenCVE Enrichment