Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Metrics
Affected Vendors & Products
References
History
Wed, 09 Apr 2025 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:* |
Thu, 20 Feb 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:enterprise_linux:8 |
Wed, 19 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:9 | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
Sat, 25 Jan 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | mysql: Optimizer unspecified vulnerability (CPU Jan 2025) | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 22 Jan 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-770 | |
Metrics |
ssvc
|
Tue, 21 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 6.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). | |
First Time appeared |
Oracle
Oracle mysql Cluster Oracle mysql Server |
|
CPEs | cpe:2.3:a:oracle:mysql_cluster:7.6.32_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_cluster:8.0.40_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_cluster:8.4.3_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_cluster:9.1.0_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:* |
|
Vendors & Products |
Oracle
Oracle mysql Cluster Oracle mysql Server |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: oracle
Published: 2025-01-21T20:53:03.419Z
Updated: 2025-01-22T18:39:20.152Z
Reserved: 2024-12-24T23:18:54.766Z
Link: CVE-2025-21518

Updated: 2025-01-22T18:39:16.296Z

Status : Analyzed
Published: 2025-01-21T21:15:17.290
Modified: 2025-04-09T16:03:17.900
Link: CVE-2025-21518
