CVE-2025-21546: Low severity oracle mysql vulnerability
Last updated 30 January 2025
Other sources
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).
— Debian
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21546?
CVE-2025-21546 is considered an easily exploitable vulnerability that allows high privileged attackers access to sensitive privileges.
How do I fix CVE-2025-21546?
To fix CVE-2025-21546, upgrade your MySQL Server to version 8.0.41-2 or later.
Which MySQL Server versions are affected by CVE-2025-21546?
CVE-2025-21546 affects MySQL Server versions 8.0.40 and earlier, 8.4.3 and earlier, and 9.1.0 and earlier.
Who is affected by CVE-2025-21546?
Any organization using affected versions of Oracle MySQL Server is at risk due to CVE-2025-21546.
Is there a workaround for CVE-2025-21546?
There is no documented workaround for CVE-2025-21546, making it essential to apply the recommended update.