CVE-2018-3077 is a denial-of-service vulnerability affecting the MySQL Server component (specifically the DDL subcomponent) in Oracle MySQL versions 5.7.22 and prior, and 8.0.11 and prior. A highly privileged attacker with network access can exploit this vulnerability to cause a complete and repeatable crash of the MySQL Server. This vulnerability has a CVSS 3.0 Base Score of 4.9 (Medium), indicating a moderate severity. The attack requires high privileges and network access, but is easily exploitable, leading to a full denial of service (availability impact). There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit or ExploitDB. The vulnerability has received minimal community discussion and media coverage, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.7.0, <= 5.7.22CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.11CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_workflow_automation:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:snapcenter:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.