VDB

CVE-2025-21501

CVE-2025-21501 PUBLISHED CVSS 9.300000190734863 CRITICAL

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle MySQL ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

EPSS 0.17% · 38.0th percentile

Risk Scores

CVSS 4.0
9.300000190734863
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS Score
0.17%
38.0th percentile

Affected Products

VendorProductVersions
OracleOracle MySQL <=9.1.0
OracleOracle MySQL 8.4.0
OracleOracle MySQL <=8.0.40
RESFRESF Rocky Linux
MariaDBMariaDB MariaDB <10.6.21
OracleOracle MySQL <=8.0.36
SUSESUSE Linux
DebianDebian Linux
MariaDBMariaDB MariaDB <10.5.28
OracleOracle MySQL <=7.6.32
OracleOracle Linux
OracleOracle MySQL <=8.4.2
NetAppNetApp ActiveIQ Unified Manager for Microsoft Windows
MariaDBMariaDB MariaDB <11.7.2
OracleOracle MySQL <=9.0.1
NetAppNetApp ActiveIQ Unified Manager
UbuntuUbuntu Linux
Red HatRed Hat Enterprise Linux
OracleOracle MySQL <=8.0.39
MariaDBMariaDB MariaDB <10.11.11

…and 2 more

Timeline

  • Dec 24, 2024 CVE ID Reserved
  • Jan 21, 2025 Coalition ESS Score
  • Jan 21, 2025 CVE Published
  • Jan 22, 2025 EPSS Score
  • Jan 23, 2025 Coalition ESS Score
  • Feb 6, 2025 EPSS Score
  • Feb 21, 2025 Coalition ESS Score
  • Feb 22, 2025 EPSS Score
  • Mar 9, 2025 EPSS Score
  • Mar 24, 2025 EPSS Score
  • Apr 8, 2025 EPSS Score
  • Apr 10, 2025 Coalition ESS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›