Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
Metrics
Affected Vendors & Products
References
History
Thu, 20 Feb 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:/a:redhat:enterprise_linux:8 |
Wed, 19 Feb 2025 15:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Redhat
Redhat enterprise Linux |
|
CPEs | cpe:/a:redhat:enterprise_linux:9 | |
Vendors & Products |
Redhat
Redhat enterprise Linux |
Tue, 18 Feb 2025 21:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 |
Thu, 23 Jan 2025 01:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Title | mysql: Privilege Misuse in MySQL Server Security Component | |
Weaknesses | CWE-269 | |
References |
| |
Metrics |
threat_severity
|
threat_severity
|
Wed, 22 Jan 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-125 | |
Metrics |
ssvc
|
Tue, 21 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N). | |
First Time appeared |
Oracle
Oracle mysql Server |
|
CPEs | cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:* cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:* |
|
Vendors & Products |
Oracle
Oracle mysql Server |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2025-02-18T20:22:15.659Z
Reserved: 2024-12-24T23:18:54.774Z
Link: CVE-2025-21546

Updated: 2025-01-22T17:58:40.476Z

Status : Awaiting Analysis
Published: 2025-01-21T21:15:20.987
Modified: 2025-02-18T21:15:26.057
Link: CVE-2025-21546
