Impact
An unauthenticated attacker with network access via HTTP can compromise an Oracle MySQL Cluster. The flaw is in cluster authentication handling and requires user interaction from a third party to enable exploitation. Successful attacks result in full takeover of the MySQL Cluster, giving the attacker complete control over the database and its data, thereby impacting confidentiality, integrity, and availability.
Affected Systems
Oracle MySQL Cluster versions 8.0.0 through 8.0.48, 8.4.0 through 8.4.11 and 9.7.0 through 9.7.2 are affected. Impacted users are those running any of these versions and exposing the cluster’s HTTP interface to external or potentially untrusted networks.
Risk and Exploitability
The CVSS v3.1 score of 7.5 reflects a high severity due to the ability to subvert authentication while requiring no privileged user access. The EPSS score indicates a very low exploitation probability (< 1%), and the lack of a KEV listing indicates no known widespread exploitation yet. However, the attacker must be able to reach the cluster over HTTP and rely on user interaction. The vulnerability is therefore high‑risk for organizations that expose the cluster to untrusted networks.
OpenCVE Enrichment