CVE-2025-50070
BaseFortify
Publication date: 2025-07-15
Last updated on: 2025-07-25
Assigner: Oracle
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| oracle | database_server | From 23.4 (inc) to 23.8 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-284 | The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in the JDBC component of Oracle Database Server versions 23.4 to 23.8. It is difficult to exploit and requires a low privileged attacker who has authenticated OS user privileges and logon access to the infrastructure where JDBC runs. The attack also requires human interaction from someone other than the attacker. Although the vulnerability is in JDBC, successful exploitation can impact additional products. The vulnerability can lead to unauthorized access to critical or all JDBC accessible data.
How can this vulnerability impact me? :
If exploited, this vulnerability can result in unauthorized access to critical data or complete access to all data accessible through JDBC. This means sensitive information could be exposed or compromised, potentially leading to data breaches or loss of data confidentiality.