PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3322 Oracle CVE debrief

CVE-2017-3322 is a low-severity Oracle MySQL Cluster issue in the NDBAPI subcomponent that can allow an unauthenticated network attacker to cause a partial denial of service. The NVD record lists affected Oracle MySQL Cluster versions as 7.2.25 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier. The published CVSS v3.0 vector indicates network access, no user interaction, and availability-only impact.

Vendor
Oracle
Product
Mysql Cluster
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Administrators and operators of Oracle MySQL Cluster deployments, especially any environment running affected 7.2, 7.3, or 7.4 releases. This matters most where the cluster is reachable over networks that an attacker could access.

Technical summary

The vulnerability is documented in the MySQL Cluster component, specifically NDBAPI. According to the NVD CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L), the issue is network reachable, requires no privileges or user interaction, and is limited to availability impact. The described outcome is an attacker being able to cause partial denial of service in MySQL Cluster.

Defensive priority

Low to routine priority: patch during normal maintenance windows, and prioritize sooner if the cluster is exposed to broader network access.

Recommended defensive actions

  • Review Oracle MySQL Cluster instances for affected versions at or below 7.2.25, 7.3.14, and 7.4.12.
  • Apply Oracle's January 2017 CPU guidance or later supported updates that remediate the issue.
  • Restrict network exposure to MySQL Cluster where possible, since the vulnerability is reachable over the network.
  • Monitor for service instability or partial availability issues in cluster environments until patched.
  • Use the NVD and Oracle advisory references to confirm remediation status in your deployment.

Evidence notes

This debrief is based on the supplied NVD record and Oracle advisory references. The source corpus identifies the issue as an Oracle MySQL Cluster NDBAPI vulnerability, with unauthenticated network attack potential and partial denial of service impact. The supplied enrichment does not mark this CVE as a Known Exploited Vulnerability.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3322 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3322

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3322 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3322

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.