PT-2025-4236 · Oracle+1 · Mysql Server

Published

2025-01-21

·

Updated

2026-02-18

·

CVE-2025-21499

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions MySQL Server versions 8.4.3 and prior MySQL Server versions 9.1.0 and prior
Description The issue allows a high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks can result in unauthorized ability to cause a hang or frequently repeatable crash of MySQL Server.
Recommendations For versions 8.4.3 and prior, update to a version later than 8.4.3 to resolve the issue. For versions 9.1.0 and prior, update to a version later than 9.1.0 to resolve the issue. As a temporary workaround, consider restricting network access to MySQL Server to minimize the risk of exploitation.

Fix

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-01184
CVE-2025-21499

Affected Products

Mysql Server