Vulnerability in Oracle Application Express Affects Multiple Versions
CVE-2025-21557
5.4MEDIUM
What is CVE-2025-21557?
An exploitable vulnerability in Oracle Application Express allows a low privileged attacker with network access via HTTP to manipulate the application. Successful exploitation requires human interaction from an entity other than the attacker. While the vulnerability resides in Oracle Application Express, its repercussions may extend to other products, leading to unauthorized updates, inserts, or deletions of accessible data within the application. Furthermore, unauthorized read access to specific data sets within Oracle Application Express is also possible.
Affected Version(s)
Oracle Application Express 23.2
Oracle Application Express 24.1