Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java VM accessible data as well as unauthorized read access to a subset of Java VM accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N).
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.oracle.com/security-alerts/cpujan2025.html |
![]() ![]() |
History
Tue, 04 Feb 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-863 | |
Metrics |
ssvc
|
Tue, 21 Jan 2025 21:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19.3-19.25, 21.3-21.16 and 23.4-23.6. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Java VM accessible data as well as unauthorized read access to a subset of Java VM accessible data. CVSS 3.1 Base Score 4.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N). | |
First Time appeared |
Oracle
Oracle database - Java Vm |
|
CPEs | cpe:2.3:a:oracle:database_-_java_vm:19.3-19.25:*:*:*:*:*:*:* cpe:2.3:a:oracle:database_-_java_vm:21.3-21.16:*:*:*:*:*:*:* cpe:2.3:a:oracle:database_-_java_vm:23.4-23.6:*:*:*:*:*:*:* |
|
Vendors & Products |
Oracle
Oracle database - Java Vm |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2025-02-04T16:03:40.301Z
Reserved: 2024-12-24T23:18:54.775Z
Link: CVE-2025-21553

Updated: 2025-01-22T15:18:10.704Z

Status : Awaiting Analysis
Published: 2025-01-21T21:15:21.880
Modified: 2025-02-04T16:15:41.797
Link: CVE-2025-21553

No data.