Junglewise Threat Intelligence

CVE-2017-3323: Oracle MySQL Cluster denial of service in Cluster: General

CVE-2017-3323 · Severity: low · CVSS 3.7 · Published 2017-01-27

Technologies: Oracle Mysql Cluster. Vendors: Oracle.

Executive brief

A vulnerability in Oracle MySQL Cluster could allow an attacker to disrupt database services. MySQL Cluster is a technology that provides high availability and high-throughput for MySQL databases. If exploited, this flaw could lead to a partial denial of service, potentially slowing down or intermittently interrupting business operations that rely on the database.

Technical details

A vulnerability in the Cluster: General subcomponent of Oracle MySQL Cluster (versions 7.2.25, 7.3.14, 7.4.12 and earlier) allows an unauthenticated attacker with network access via multiple protocols to compromise the system. The vulnerability is classified as difficult to exploit (High Attack Complexity). Successful exploitation results in a partial denial of service (Availability impact), though it does not provide access to data or allow for unauthorized modifications. The root cause is related to improper input validation (CWE-20). Oracle addressed this in the January 2017 Critical Patch Update.

Affected products

  • Oracle MySQL Cluster 7.2.25 and earlier, 7.3.14 and earlier, 7.4.12 and earlier

Timeline

  • 2017-01-27: disclosed
  • 2017-01-27: advisory: Oracle Critical Patch Update published

References

Related threats