PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3322 Oracle CVE debrief

CVE-2017-3322 is a low-severity Oracle MySQL Cluster issue in the NDBAPI subcomponent that can allow an unauthenticated network attacker to cause a partial denial of service. The NVD record lists affected Oracle MySQL Cluster versions as 7.2.25 and earlier, 7.3.14 and earlier, and 7.4.12 and earlier. The published CVSS v3.0 vector indicates network access, no user interaction, and availability-only impact.

Vendor
Oracle
Product
CVE-2017-3322
CVSS
LOW 3.7
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Administrators and operators of Oracle MySQL Cluster deployments, especially any environment running affected 7.2, 7.3, or 7.4 releases. This matters most where the cluster is reachable over networks that an attacker could access.

Technical summary

The vulnerability is documented in the MySQL Cluster component, specifically NDBAPI. According to the NVD CVSS vector (AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L), the issue is network reachable, requires no privileges or user interaction, and is limited to availability impact. The described outcome is an attacker being able to cause partial denial of service in MySQL Cluster.

Defensive priority

Low to routine priority: patch during normal maintenance windows, and prioritize sooner if the cluster is exposed to broader network access.

Recommended defensive actions

  • Review Oracle MySQL Cluster instances for affected versions at or below 7.2.25, 7.3.14, and 7.4.12.
  • Apply Oracle's January 2017 CPU guidance or later supported updates that remediate the issue.
  • Restrict network exposure to MySQL Cluster where possible, since the vulnerability is reachable over the network.
  • Monitor for service instability or partial availability issues in cluster environments until patched.
  • Use the NVD and Oracle advisory references to confirm remediation status in your deployment.

Evidence notes

This debrief is based on the supplied NVD record and Oracle advisory references. The source corpus identifies the issue as an Oracle MySQL Cluster NDBAPI vulnerability, with unauthenticated network attack potential and partial denial of service impact. The supplied enrichment does not mark this CVE as a Known Exploited Vulnerability.

Official resources

CVE published on 2017-01-27 and last modified in the supplied record on 2026-05-13. The Oracle advisory referenced by NVD is the January 2017 Critical Patch Update.