Denial of Service Vulnerability in MySQL Server by Oracle
CVE-2025-30699

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 April 2025

Summary

A vulnerability in Oracle's MySQL Server, specifically within the stored procedure component, allows attackers with high privileges and network access to exploit the system. Affected versions include 8.0.0-8.0.41, 8.4.0-8.4.4, and 9.0.0-9.2.0. Exploiting this vulnerability can lead to unauthorized operations that may result in frequent crashes or a complete denial of service, affecting the availability of the MySQL Server.

Affected Version(s)

MySQL Server 8.0.0 <= 8.0.41

MySQL Server 8.4.0 <= 8.4.4

MySQL Server 9.0.0 <= 9.2.0

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.