CVE-2023-22115 is a denial-of-service vulnerability affecting Oracle MySQL Server versions 8.0.33 and prior, specifically within the Server: DML component. A highly privileged attacker with network access can exploit this vulnerability to cause a complete system crash or hang of the MySQL Server. With a CVSS 3.1 Base Score of 4.9, it is rated as medium severity, indicating a low attack complexity but significant availability impact. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is there any evidence of active exploitation or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 8.0, <= 8.0.33CPE matchmatch criteria | cpe:2.3:a:oracle:mysql:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:oncommand_insight:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
mysql: Server: DML unspecified vulnerability (CPU Oct 2023)
Oct 17, 2023Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
Oct 10, 2023