← Back to CVE List
CVE-2025-49719NVD
Vulnerability Summary
Improper input validation in SQL Server allows an unauthorized attacker to disclose information over a network.
CVSS v3.1 Base Metrics — Score 7.5 (HIGH)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityNone
AvailabilityNone
Affected & Patched Versions
- Microsoft Sql Server 2016 >= 13.0.6300.2 and < 13.0.6460.7
- Microsoft Sql Server 2016 >= 13.0.7000.253 and < 13.0.7055.9
- Microsoft Sql Server 2017 >= 14.0.1000.169 and < 14.0.2075.8
- Microsoft Sql Server 2017 >= 14.0.3006.16 and < 14.0.3495.9
- Microsoft Sql Server 2019 >= 15.0.2000.5 and < 15.0.2135.5
- Microsoft Sql Server 2019 >= 15.0.4003.23 and < 15.0.4435.7
- Microsoft Sql Server 2022 >= 16.0.1000.6 and < 16.0.1140.6
- Microsoft Sql Server 2022 >= 16.0.4003.1 and < 16.0.4200.1
- Microsoft Sql Server 2016 13.0.6460.7
- Microsoft Sql Server 2016 13.0.7055.9
- Microsoft Sql Server 2017 14.0.2075.8
- Microsoft Sql Server 2017 14.0.3495.9
- Microsoft Sql Server 2019 15.0.2135.5
- Microsoft Sql Server 2019 15.0.4435.7
- Microsoft Sql Server 2022 16.0.1140.6
- Microsoft Sql Server 2022 16.0.4200.1