CVE-2019-2632: High severity ORACLE MySQL vulnerability
Last updated 25 August 2025
Other sources
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server : Pluggable Auth). Supported versions that are affected are 5.7.25 and prior and 8.0.15 and prior. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all MySQL Server accessible data. CVSS 3.0 Base Score 7.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N).
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2632?
CVE-2019-2632 has a CVSS score indicating a high severity due to its easily exploitable nature allowing unauthorized access.
Which versions of MySQL are affected by CVE-2019-2632?
CVE-2019-2632 affects MySQL Server versions 5.7.25 and prior, and 8.0.15 and prior.
How do I fix CVE-2019-2632?
To remediate CVE-2019-2632, upgrade to the latest MySQL version beyond the affected releases.
Can CVE-2019-2632 be exploited remotely?
Yes, CVE-2019-2632 allows unauthenticated attackers with network access to exploit the vulnerability.
What component of MySQL is impacted by CVE-2019-2632?
CVE-2019-2632 impacts the MySQL Server component, specifically in the Pluggable Authentication feature.