PT-2025-4287 · Oracle+1 · Mysql Server
Published
2025-01-21
·
Updated
2025-04-08
·
CVE-2025-21566
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MySQL Server versions 9.1.0 and prior
Description
The issue is related to the Server: Optimizer component of MySQL Server, which can be easily exploited by an attacker with low privileges and network access via multiple protocols. This can lead to unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server, resulting in availability impacts.
Recommendations
For versions 9.1.0 and prior, update to a version that contains a fix for this issue.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mysql Server