CVE-2025-21520
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N
- Puntuación base: 1.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.30%
- Percentil entre todas las CVEs puntuadas: 21
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (2)
CWE
- CWE-732
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-21520",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-21520",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-22T18:35:04.827489Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert_us@oracle.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 1.8,
"attackVector": "LOCAL",
"baseSeverity": "LOW",
"vectorString": "CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N",
"integrityImpact": "NONE",
"userInteraction": "REQUIRED",
"attackComplexity": "HIGH",
"availabilityImpact": "NONE",
"privilegesRequired": "HIGH",
"confidentialityImpact": "LOW"
},
"impactScore": 1.4,
"exploitabilityScore": 0.3
}
]
},
"affected": [
{
"source": "secalert_us@oracle.com",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:oracle:mysql_cluster:7.6.32_and_prior:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_cluster:8.0.40_and_prior:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_cluster:8.4.3_and_prior:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_cluster:9.1.0_and_prior:*:*:*:*:*:*:*"
],
"vendor": "Oracle Corporation",
"product": "MySQL Cluster",
"versions": [
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "7.6.32"
},
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "8.0.40"
},
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "8.4.3"
},
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "9.1.0"
}
]
},
{
"cpes": [
"cpe:2.3:a:oracle:mysql_server:8.0.40_and_prior:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_server:8.4.3_and_prior:*:*:*:*:*:*:*",
"cpe:2.3:a:oracle:mysql_server:9.1.0_and_prior:*:*:*:*:*:*:*"
],
"vendor": "Oracle Corporation",
"product": "MySQL Server",
"versions": [
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "8.0.40"
},
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "8.4.3"
},
{
"status": "affected",
"version": "*",
"versionType": "custom",
"lessThanOrEqual": "9.1.0"
}
]
}
]
}
],
"published": "2025-01-21T21:15:17.537",
"references": [
{
"url": "https://www.oracle.com/security-alerts/cpujan2025.html",
"tags": [
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
},
{
"url": "https://security.netapp.com/advisory/ntap-20250131-0004/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Options). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Difficult to exploit vulnerability allows high privileged attacker with logon to the infrastructure where MySQL Server executes to compromise MySQL Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 1.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N)."
},
{
"lang": "es",
"value": "Vulnerabilidad en el producto MySQL Server de Oracle MySQL (componente: Server: Options). Las versiones compatibles afectadas son 8.0.40 y anteriores, 8.4.3 y anteriores y 9.1.0 y anteriores. Esta vulnerabilidad, que es difícil de explotar, permite que un atacante con privilegios elevados y que inicie sesión en la infraestructura donde se ejecuta MySQL Server pueda comprometer MySQL Server. Los ataques exitosos requieren la interacción humana de una persona distinta del atacante. Los ataques exitosos de esta vulnerabilidad pueden dar como resultado un acceso de lectura no autorizado a un subconjunto de datos accesibles de MySQL Server. Puntuación base CVSS 3.1 1.8 (impactos de confidencialidad). Vector CVSS: (CVSS:3.1/AV:L/AC:H/PR:H/UI:R/S:U/C:L/I:N/A:N)."
}
],
"lastModified": "2026-06-17T08:43:39.910",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4AFAE8F8-2FAD-4A31-9AAD-93DCA1AA990E",
"versionEndIncluding": "7.6.32",
"versionStartIncluding": "7.6.0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42E28B08-50A1-422B-9181-191B6C40F226",
"versionEndIncluding": "8.0.40",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "075176A9-E7B6-4ED3-8E2D-5F5034853EFC",
"versionEndIncluding": "8.4.3",
"versionStartIncluding": "8.4.0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql_cluster:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D9CBDD9-F240-4C17-9211-E16344DD6B12",
"versionEndIncluding": "9.1.0",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AF091998-B545-474D-A31F-ED2C971AA64A",
"versionEndIncluding": "8.0.40",
"versionStartIncluding": "8.0.0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B10E8F6D-041F-410A-90BA-461AD19DB569",
"versionEndIncluding": "8.4.3",
"versionStartIncluding": "8.4.0"
},
{
"criteria": "cpe:2.3:a:oracle:mysql_server:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BE5CCDEC-E9CF-4D97-AA17-39DF462918AB",
"versionEndIncluding": "9.1.0",
"versionStartIncluding": "9.0.0"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert_us@oracle.com"
}