Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
History

Thu, 17 Apr 2025 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle
Oracle secure Backup
CPEs cpe:2.3:a:oracle:secure_backup:12.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:12.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:12.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.2:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle secure Backup

Wed, 16 Apr 2025 21:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-732
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 15 Apr 2025 20:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2025-04-17T03:55:20.071Z

Reserved: 2024-12-24T23:18:54.785Z

Link: CVE-2025-21578

cve-icon Vulnrichment

Updated: 2025-04-16T20:32:30.571Z

cve-icon NVD

Status : Analyzed

Published: 2025-04-15T21:15:48.240

Modified: 2025-04-17T21:37:12.170

Link: CVE-2025-21578

cve-icon Redhat

No data.