Executive brief
A vulnerability exists in the Java VM component of Oracle Database Server, which is used to run Java-based applications and procedures within the database. An attacker with basic database access could exploit this flaw to modify or delete critical business data. This could lead to data corruption or unauthorized changes to sensitive records, though it does not directly allow for data theft or service shutdowns.
Technical details
An integrity vulnerability exists in the Java VM component of Oracle Database Server. The flaw is easily exploitable by a low-privileged attacker who possesses 'Create Session' privileges and network access via Oracle Net. Successful exploitation allows the attacker to compromise the Java VM environment, leading to unauthorized creation, deletion, or modification of data accessible to the Java VM. The vulnerability affects versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2. Fixes are typically delivered via Oracle's Critical Patch Update (CPU) program.
Affected products
- Oracle Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2
Timeline
- 2026-07-21: advisory: Oracle published the vulnerability details in the July 2026 CPU.
- 2026-07-21: disclosed