Server Exploit in MySQL Database Product by Oracle
CVE-2025-30682

6.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability has been identified in the MySQL Server product of Oracle MySQL, specifically within the optimizer component. This issue permits low-privilege attackers with network access via various protocols to compromise the MySQL Server. When successfully exploited, this vulnerability can lead to unauthorized disruptions, including the potential for a complete denial of service through server hangs or repetitive crashes. The supported affected versions include MySQL Server 8.0.0 through 8.0.41, 8.4.0 through 8.4.4, and 9.0.0 through 9.2.0.

Affected Version(s)

MySQL Server 8.0.0 <= 8.0.41

MySQL Server 8.4.0 <= 8.4.4

MySQL Server 9.0.0 <= 9.2.0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.