Executive brief
A vulnerability exists in the JDBC component of Oracle Database Server, which is used by applications to communicate with the database. An unauthenticated attacker could exploit this over a network to modify, create, or delete critical business data. Successful exploitation requires a legitimate user to perform an action, such as clicking a link or opening a malicious file, which could lead to significant data integrity issues.
Technical details
This vulnerability affects the Java Database Connectivity (JDBC) component of Oracle Database Server. It is classified as an integrity-impacting flaw that can be exploited by an unauthenticated attacker with network access via the Oracle Net protocol. The attack is considered 'easily exploitable' but requires user interaction (UI:R) to succeed. If successful, the attacker can perform unauthorized creation, deletion, or modification of all JDBC-accessible data. The vulnerability lacks confidentiality or availability impacts according to the CVSS vector. Affected versions include 19c (19.3-19.31), 21c (21.3-21.22), and 23c (23.4.0-23.26.2).
Affected products
- Oracle Database Server 19.3-19.31, 21.3-21.22, 23.4.0-23.26.2
Timeline
- 2026-07-21: disclosed: Initial advisory publication