Oracle Database Server Java VM Vulnerability Allowing Unauthorized Data Access

Vulnerability

A vulnerability has been identified in the Java VM component of Oracle Database Server, affecting versions 19.3 through 19.27 and 21.3 through 21.18. This easily exploitable vulnerability allows a low-privileged attacker with Create Session and Create Procedure privileges, and network access via Oracle Net, to compromise the Java VM. While the vulnerability resides in the Java VM, successful exploitation could significantly impact additional products, leading to a scope change. Attacks exploiting this vulnerability could result in unauthorized access to critical data or complete access to all data accessible by the Java VM.

Impact

Exploitation of this vulnerability could lead to unauthorized access to critical data or complete access to all data accessible by the Java VM.

Added: Jul 15, 2025, 10:27 PM
Updated: Jul 15, 2025, 10:27 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
5.2
remediation
0.0
relevance
0.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.