Executive brief
A vulnerability exists in Oracle MySQL Cluster, a high-availability database solution. An unauthenticated attacker could remotely cause a partial denial of service, potentially impacting the availability of database services. While the flaw is difficult to exploit, it could lead to temporary disruptions in operations or application performance.
Technical details
This vulnerability is classified as an improper input validation issue (CWE-20) within the 'Cluster: General' subcomponent of Oracle MySQL Cluster. It is accessible via multiple protocols over the network without authentication. The attack complexity is rated as high, suggesting that successful exploitation may require specific timing or environmental conditions. If exploited, the vulnerability results in a partial denial of service (Availability impact), though it does not compromise data confidentiality or integrity. Patches were released as part of the Oracle Critical Patch Update in January 2017.
Affected products
- Oracle MySQL Cluster 7.2.19 and earlier, 7.3.8 and earlier, 7.4.5 and earlier
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published