CVE-2025-21584
CVSS 3.1 Score 4.9 of 10 (medium)
Details
Published Apr 15, 2025
Updated: Apr 21, 2025
CWE ID 732
Summary
CVE-2025-21584 is a newly disclosed vulnerability affecting Oracle MySQL Server versions 8.0.0-8.0.41, 8.4.0-8.4.4, and 9.0.0-9.2.0. This issue lies within the DDL component and can be exploited by high-privileged attackers with network access, using multiple protocols. Consequences of successful attacks include the ability to cause a denial-of-service (DoS) by inducing a hang or frequent crashes in MySQL Server (CVSS Base Score: 4.9, Availability impact).
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Oracle MySQL Server
- MySQL
Affected Vendors
- Oracle