PatchSiren cyber security CVE debrief
CVE-2017-3322 Oracle CVE debrief
CVE-2017-3322 is a low-severity Oracle MySQL Cluster issue in the NDBAPI subcomponent that can allow an unauthenticated network attacker to cause a partial denial of service. The NVD record lists affected Oracle MySQL Cluster versions as 7.2.25 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier. The published CVSS v3.0 vector indicates network access, no user interaction, and availability-only impact.
- Vendor
- Oracle
- Product
- Mysql Cluster
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators of Oracle MySQL Cluster deployments, especially any environment running affected 7.2, 7.3, or 7.4 releases. This matters most where the cluster is reachable over networks that an attacker could access.
Technical summary
The vulnerability is documented in the MySQL Cluster component, specifically NDBAPI. According to the NVD CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L), the issue is network reachable, requires no privileges or user interaction, and is limited to availability impact. The described outcome is an attacker being able to cause partial denial of service in MySQL Cluster.
Defensive priority
Low to routine priority: patch during normal maintenance windows, and prioritize sooner if the cluster is exposed to broader network access.
Recommended defensive actions
- Review Oracle MySQL Cluster instances for affected versions at or below 7.2.25, 7.3.14, and 7.4.12.
- Apply Oracle's January 2017 CPU guidance or later supported updates that remediate the issue.
- Restrict network exposure to MySQL Cluster where possible, since the vulnerability is reachable over the network.
- Monitor for service instability or partial availability issues in cluster environments until patched.
- Use the NVD and Oracle advisory references to confirm remediation status in your deployment.
Evidence notes
This debrief is based on the supplied NVD record and Oracle advisory references. The source corpus identifies the issue as an Oracle MySQL Cluster NDBAPI vulnerability, with unauthenticated network attack potential and partial denial of service impact. The supplied enrichment does not mark this CVE as a Known Exploited Vulnerability.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3322 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3322
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3322 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3322
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.