Executive brief
A vulnerability exists in the MySQL Cluster component of Oracle MySQL, specifically within the NDBAPI subcomponent. This flaw could allow an unauthenticated attacker to remotely cause a partial denial of service, potentially impacting the availability of the database cluster. While the vulnerability is difficult to exploit, it could disrupt normal business operations and data availability.
Technical details
The vulnerability is located in the NDBAPI subcomponent of Oracle MySQL Cluster. It is classified as a denial of service (DoS) vulnerability that can be triggered by an unauthenticated attacker with network access via multiple protocols. The attack complexity is rated as high, suggesting that successful exploitation requires specific conditions or timing. If exploited, the vulnerability results in a partial impact on the availability of the MySQL Cluster. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle MySQL Cluster 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle Critical Patch Update published