CVE-2025-21500

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21500 is a vulnerability affecting Oracle MySQL Server versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This issue lies in the Optimizer component and can be exploited by a low-privileged attacker with network access, leading to a denial-of-service (DoS) condition. Successful attacks may result in a MySQL Server hang or frequent crashes. The Common Vulnerability Scoring System (CVSS) rates this vulnerability with a base score of 6.5 for availability impacts. The attack vector includes network access with a low level of complexity.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share