FlawAtlas
Search the atlas
UBUNTU-CVE-2025-21546 Low

UBUNTU-CVE-2025-21546

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).

Exploit probability Not scored
Published January 21, 2025
Required by Not available
Last source change April 22, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:14.04:LTS mysql-5.5

25 explicit affected versions

Ubuntu:16.04:LTS percona-server-5.6

3 explicit affected versions

Ubuntu:16.04:LTS percona-xtradb-cluster-5.6

8 explicit affected versions

Ubuntu:20.04:LTS mysql-8.0

36 explicit affected versions

Ubuntu:22.04:LTS mysql-8.0

20 explicit affected versions

Ubuntu:24.04:LTS mysql-8.0

11 explicit affected versions

Ubuntu:Pro:16.04:LTS mysql-5.7

36 explicit affected versions

Ubuntu:Pro:18.04:LTS mysql-5.7

28 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities UBUNTU-CVE-2025-21546

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Security: Privileges). Supported versions that are affected are 8.0.40 and prior, 8.4.3 and prior and 9.1.0 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of MySQL Server accessible data as well as unauthorized read access to a subset of MySQL Server accessible data. CVSS 3.1 Base Score 3.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:N).

View original source

05 / REFERENCES

Further evidence