Privilege Escalation Vulnerability in MySQL Server by Oracle
CVE-2025-21540

5.4MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
21 January 2025

Summary

A vulnerability exists in Oracle's MySQL Server that affects several supported versions, enabling low-privileged attackers with network access to exploit the system. Successful exploitation may allow unauthorized manipulation of data, including updates and deletions, as well as unauthorized reading of sensitive data. Given the vast usage of MySQL, organizations should assess their systems and apply necessary patches to mitigate risk.

Affected Version(s)

MySQL Server * <= 8.0.40

MySQL Server * <= 8.4.3

MySQL Server * <= 9.1.0

References

CVSS V3.1

Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.