- Description
- Vulnerability in the MySQL Router product of Oracle MySQL (component: Router: General). Supported versions that are affected are 8.4.0-8.4.10 and 9.7.0-9.7.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise MySQL Router. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Router. CVSS 3.1 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
- Source
- secalert_us@oracle.com
- NVD status
- Analyzed
- Products
- mysql_router
CVSS 3.1
- Type
- Secondary
- Base score
- 7.5
- Impact score
- 3.6
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- HIGH
- 134c704f-9b21-4f2e-91b3-4a467353bcc0
- CWE-400
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:mysql_router:*:*:*:*:*:*:*:*",
"matchCriteriaId": "A13721AA-321C-4E34-8A96-413227115A3E",
"versionEndIncluding": "8.4.10",
"versionStartIncluding": "8.4.0",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oracle:mysql_router:9.7.0:*:*:*:*:*:*:*",
"matchCriteriaId": "A6E5489F-A6EE-4C87-9106-4D5055573962",
"vulnerable": true
},
{
"criteria": "cpe:2.3:a:oracle:mysql_router:9.7.1:*:*:*:*:*:*:*",
"matchCriteriaId": "919B46A0-319C-4E30-8C73-685F0B3F8438",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]