Vulnerability in Oracle MySQL Server Affects Multiple Versions
CVE-2025-30688
6.5MEDIUM
Summary
A vulnerability in Oracle MySQL Server's optimizer component allows low privileged attackers with network access to exploit it through various protocols. This issue can lead to unauthorized denial of service, causing the MySQL Server to hang or crash repeatedly. Affected versions are 8.0.0 - 8.0.41, 8.4.0 - 8.4.4, and 9.0.0 - 9.2.0, posing significant risks for organizations relying on these MySQL releases.
Affected Version(s)
MySQL Server 8.0.0 <= 8.0.41
MySQL Server 8.4.0 <= 8.4.4
MySQL Server 9.0.0 <= 9.2.0
References
CVSS V3.1
Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved