PatchSiren cyber security CVE debrief
CVE-2017-3322 Oracle CVE debrief
CVE-2017-3322 is a low-severity Oracle MySQL Cluster issue in the NDBAPI subcomponent that can allow an unauthenticated network attacker to cause a partial denial of service. The NVD record lists affected Oracle MySQL Cluster versions as 7.2.25 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier. The published CVSS v3.0 vector indicates network access, no user interaction, and availability-only impact.
- Vendor
- Oracle
- Product
- CVE-2017-3322
- CVSS
- LOW 3.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Administrators and operators of Oracle MySQL Cluster deployments, especially any environment running affected 7.2, 7.3, or 7.4 releases. This matters most where the cluster is reachable over networks that an attacker could access.
Technical summary
The vulnerability is documented in the MySQL Cluster component, specifically NDBAPI. According to the NVD CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L), the issue is network reachable, requires no privileges or user interaction, and is limited to availability impact. The described outcome is an attacker being able to cause partial denial of service in MySQL Cluster.
Defensive priority
Low to routine priority: patch during normal maintenance windows, and prioritize sooner if the cluster is exposed to broader network access.
Recommended defensive actions
- Review Oracle MySQL Cluster instances for affected versions at or below 7.2.25, 7.3.14, and 7.4.12.
- Apply Oracle's January 2017 CPU guidance or later supported updates that remediate the issue.
- Restrict network exposure to MySQL Cluster where possible, since the vulnerability is reachable over the network.
- Monitor for service instability or partial availability issues in cluster environments until patched.
- Use the NVD and Oracle advisory references to confirm remediation status in your deployment.
Evidence notes
This debrief is based on the supplied NVD record and Oracle advisory references. The source corpus identifies the issue as an Oracle MySQL Cluster NDBAPI vulnerability, with unauthenticated network attack potential and partial denial of service impact. The supplied enrichment does not mark this CVE as a Known Exploited Vulnerability.
Official resources
-
CVE-2017-3322 CVE record
CVE.org
-
CVE-2017-3322 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
- Source reference
- Source reference
CVE published on 2017-01-27 and last modified in the supplied record on 2026-05-13. The Oracle advisory referenced by NVD is the January 2017 Critical Patch Update.