Executive brief
Oracle MySQL Cluster is a high-availability database technology used for mission-critical applications. A vulnerability in its NDBAPI component could allow an unauthenticated attacker to remotely modify or delete database records and cause partial service disruptions. While difficult to exploit, this flaw poses a risk to data integrity and the continuous availability of database services.
Technical details
This vulnerability exists in the NDBAPI subcomponent of Oracle MySQL Cluster (versions 7.2.26, 7.3.14, 7.4.12 and earlier). It is classified as a 'difficult to exploit' flaw that allows an unauthenticated attacker with network access via multiple protocols to compromise the cluster. Successful exploitation can result in unauthorized update, insert, or delete access to accessible data, as well as the ability to cause a partial denial of service (DoS). The vulnerability is tracked as CVE-2016-5541 and was addressed in the Oracle Critical Patch Update for January 2017.
Affected products
- Oracle MySQL Cluster 7.2.26 and earlier, 7.3.14 and earlier, 7.4.12 and earlier
Timeline
- 2017-01-27: advisory: NVD publication date
- 2017-01-17: patched: Oracle January 2017 Critical Patch Update released