Executive brief
A vulnerability exists in the JDBC component of Oracle Database Server, which is used to connect applications to the database. A high-privileged attacker could exploit this flaw to take control of the JDBC component, potentially compromising the confidentiality and integrity of the data it handles. Successful exploitation requires a legitimate user to interact with the system, making it a significant risk for organizations relying on these database versions for their operations.
Technical details
A vulnerability in the JDBC component of Oracle Database Server (versions 19.3-19.31, 21.3-21.22, and 23.4.0-23.26.2) allows for a component takeover. The flaw is exploitable by a high-privileged attacker with network access via Oracle Net. While the attack is considered easily exploitable (AC:L), it requires human interaction (UI:R) from a person other than the attacker to succeed. Successful exploitation results in high impacts to confidentiality, integrity, and availability (C:H/I:H/A:H). Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.
Affected products
- Oracle Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2
Timeline
- 2026-07-21: disclosed: Initial publication of CVE-2026-47045 by Oracle.