CVE-2018-3247 is a medium-severity vulnerability affecting the MySQL Server component (specifically the Server: Merge subcomponent) in Oracle MySQL versions 5.6.41 and prior, 5.7.23 and prior, and 8.0.12 and prior. This easily exploitable flaw allows a high-privileged attacker with network access to cause a complete denial of service (DOS) through a repeatable crash or hang, and unauthorized data modification (insert, update, delete). The CVSS 3.0 base score is 5.5, indicating low integrity impact and high availability impact. There is currently no known public exploit code (Metasploit, Nuclei, ExploitDB), nor is it listed on CISA's KEV catalog, and it has garnered minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.6.0, <= 5.6.41CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 5.7.0, <= 5.7.23CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
>= 8.0.0, <= 8.0.12CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* | ||
>= 9.4CPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_unified_manager:*:*:*:*:*:vmware_vsphere:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.