Skip to main content

Incorrect Permission Assignment for Critical Resource

CVE-2025-30688

Severity Medium
Score 6.5/10

Summary

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). An easily exploitable vulnerability allows a low-privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or a frequently repeatable crash (complete DoS) of MySQL Server. This issue affects mysql-server versions 8.0.0 through 8.0.41, 8.4.0 through 8.4.4, and 9.0.0-release through 9.2.0.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • LOW
  • NONE
  • HIGH

CWE-732 - Incorrect Permission Assignment for Critical Resource

The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Advisory Timeline

  • Published