PT-2025-29640 · Oracle+7 · Mysql Server+6

Published

2025-07-15

·

Updated

2025-10-06

·

CVE-2025-50087

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions MySQL Server versions 8.0.0 through 8.0.42 MySQL Server versions 8.4.0 through 8.4.5 MySQL Server versions 9.0.0 through 9.3.0
Description A vulnerability exists in the Optimizer component of Oracle MySQL Server. Successful exploitation of this issue can lead to unauthorized creation, deletion, or modification of critical data accessible by MySQL Server. The vulnerability is easily exploitable and allows a high-privileged attacker with network access via multiple protocols to compromise the server.
Recommendations MySQL Server versions prior to 8.0.43 should be used. MySQL Server versions prior to 8.4.6 should be used. MySQL Server versions prior to 9.3.1 should be used.

Fix

DoS

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:15699
ALSA-2025:16046
ALSA-2025:16086
ALSA-2025:16861
AZL-65288
AZL-65462
BDU:2025-08700
CESA-2025_16861
CVE-2025-50087
INFSA-2025_16046
INFSA-2025_16086
INFSA-2025_16861
OESA-2025-2085
RHSA-2025:16861
RHSA-2025_16046
RHSA-2025_16086
RHSA-2025_16861
USN-7691-1
USN-7691-2

Affected Products

Almalinux
Centos
Linuxmint
Mysql Server
Red Hat
Rocky Linux
Ubuntu