Oracle Database Server Java VM Vulnerability Allowing Unauthenticated Data Modification

Vulnerability

A vulnerability has been identified in the Java VM component of Oracle Database Server. This issue affects versions 19.3 through 19.28, 21.3 through 21.19, and 23.4 through 23.9. The vulnerability is difficult to exploit but allows an unauthenticated attacker with network access via Oracle Net to compromise the Java VM. Successful exploitation could lead to unauthorized creation, deletion, or modification of critical data, or any data accessible to the Java VM.

Impact

Exploitation of this vulnerability could result in unauthorized changes to critical data or any data accessible through the Java VM.

Added: Oct 21, 2025, 9:06 PM
Updated: Oct 21, 2025, 9:06 PM

Vulnerability Rating

Custom Algorithm
spread
7.3
impact
2.5
exploitability
7.4
remediation
0.0
relevance
0.8
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.