CVE-2025-21555

CVSS 3.1 Score 5.5 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21555 is a vulnerability affecting the InnoDB component of Oracle MySQL Servers, specifically versions 8.0.40 and prior, 8.4.3 and prior, and 9.1.0 and prior. This easily exploitable issue allows a high privileged attacker with network access to compromise the server via multiple protocols. Successful attacks can result in a hang or frequent crash of MySQL Server, leading to a Denial of Service (DoS), as well as unauthorized update, insert, or delete access to certain data. The vulnerability has a base score of 5.5 on the CVSS 3.1 scale, with high impacts on Integrity and Availability.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share