Skip to main content
Vulnerability Database/CVE-2025-21567

CVE-2025-21567: Oracle MySQL Server Information Disclosure

CVE-2025-21567 is an information disclosure flaw in Oracle MySQL Server that allows low privileged attackers to gain unauthorized read access to sensitive data. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2025-21567 Overview

CVE-2025-21567 is an authorization flaw in the Oracle MySQL Server Server: Security: Privileges component. The vulnerability affects MySQL Server versions 9.1.0 and prior. An authenticated attacker with low privileges and network access can exploit the flaw over multiple protocols to gain unauthorized read access to a subset of MySQL Server data. The vulnerability is classified under CWE-863: Incorrect Authorization and impacts confidentiality only. Oracle disclosed the issue in its Critical Patch Update for January 2025.

Critical Impact

Low-privileged database users can read data they should not be authorized to access, breaching tenant isolation in shared MySQL deployments.

Affected Products

  • Oracle MySQL Server 9.1.0
  • Oracle MySQL Server prior releases in the 9.x line
  • NetApp products bundling affected MySQL Server versions (see NetApp advisory)

Discovery Timeline

  • 2025-01-21 - CVE-2025-21567 published to NVD following Oracle's January 2025 Critical Patch Update
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-21567

Vulnerability Analysis

The vulnerability resides in the privilege enforcement logic within the MySQL Server Server: Security: Privileges subsystem. An authenticated user with low privileges can bypass intended authorization checks and read data that should be restricted by the server's access control model. Exploitation requires network access and valid credentials but does not require user interaction. Because the flaw returns only a subset of accessible data and does not permit modification, integrity and availability remain intact. The issue is tracked under CWE-863: Incorrect Authorization, meaning the server performs an authorization check but reaches the wrong decision under specific conditions.

Root Cause

The root cause is an incorrect authorization decision inside the MySQL privilege subsystem. Oracle has not published detailed technical internals for this issue. The behavior aligns with CWE-863, where a control path grants access despite the requesting principal lacking the required privilege for a given object or operation.

Attack Vector

Exploitation is remote and network-based. The attacker must hold a valid MySQL account with low privileges. The advisory notes exploitation is possible over multiple protocols supported by MySQL Server, which typically includes the classic MySQL protocol and MySQL X Protocol. No specific victim interaction is required. A successful attack yields unauthorized read access to a subset of server-side data, such as rows, columns, or schema metadata that fall outside the attacker's granted privileges.

No public proof-of-concept exploit is available and the CVE is not listed in the CISA Known Exploited Vulnerabilities catalog. See the Oracle Security Alert January 2025 and NetApp Security Advisory NTAP-20250124-0014 for vendor guidance.

Detection Methods for CVE-2025-21567

Indicators of Compromise

  • Unexpected SELECT, SHOW, or metadata queries issued by low-privileged accounts against schemas or tables outside their normal working set.
  • Authentication activity from low-privileged accounts over the X Protocol port (default 33060) when only classic protocol traffic is expected.
  • Result-set sizes or query cardinality anomalies that deviate from an account's historical baseline.

Detection Strategies

  • Enable the MySQL Enterprise Audit plugin or audit_log and alert on privilege-sensitive statements executed by non-administrative users.
  • Correlate performance_schema and general query logs to identify accounts that access objects not granted through mysql.user, mysql.db, or role assignments.
  • Baseline query patterns per service account and flag deviations, particularly access to information_schema objects describing tables the account does not own.

Monitoring Recommendations

  • Forward MySQL audit and error logs to a centralized analytics platform for retention and cross-source correlation.
  • Monitor for repeated failed authorization events followed by successful reads on the same objects, which can indicate probing behavior.
  • Track version strings returned by SELECT VERSION() across the fleet to identify unpatched MySQL Server 9.1.0 or earlier instances.

How to Mitigate CVE-2025-21567

Immediate Actions Required

  • Apply the patches from the Oracle Critical Patch Update January 2025 to all MySQL Server 9.1.0 and earlier instances.
  • Inventory MySQL accounts and remove unused low-privileged users that could be leveraged for exploitation.
  • Restrict network exposure of MySQL ports (3306, 33060) to trusted application subnets using host firewalls and security groups.

Patch Information

Oracle addressed CVE-2025-21567 in the January 2025 Critical Patch Update. Administrators should upgrade Oracle MySQL Server to the fixed release published in that advisory. NetApp customers should consult NetApp Security Advisory NTAP-20250124-0014 for guidance on affected NetApp products that embed MySQL Server.

Workarounds

  • Review and tighten GRANT statements so low-privileged accounts hold only the minimum object-level privileges required.
  • Disable protocols that are not in use, for example the X Protocol via mysqlx=OFF, to reduce the attack surface.
  • Enforce network-level access control lists so that MySQL is reachable only from authorized application hosts.
bash
# Configuration example: verify version and restrict X Protocol if unused
mysql -u admin -p -e "SELECT VERSION();"

# In /etc/mysql/my.cnf under [mysqld]
# mysqlx=OFF
# bind-address=10.0.0.25

systemctl restart mysql

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.