CVE-2025-59250
Improper input validation in JDBC Driver for SQL Server allows an unauthorized attacker to perform spoofing over a network.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2025-59250, https://github.com/microsoft/mssql-jdbc/pull/2798, https://github.com/microsoft/mssql-jdbc/pull/2800, https://github.com/microsoft/mssql-jdbc/pull/2801, https://github.com/microsoft/mssql-jdbc/pull/2802, https://github.com/microsoft/mssql-jdbc/pull/2803, https://github.com/microsoft/mssql-jdbc/pull/2807, https://github.com/microsoft/mssql-jdbc/commit/9732e1bbc6ec44166fda2cddab31ce1c86c873dd#diff-45367b99a1951943bfecfc7765e80df687967aa56286a5b2e039f77cd9a0e118, https://github.com/microsoft/mssql-jdbc, https://github.com/microsoft/mssql-jdbc/blob/main/CHANGELOG.md, https://learn.microsoft.com/en-us/sql/connect/jdbc/microsoft-jdbc-driver-for-sql-server-support-matrix, https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59250
