Vulnerability in Oracle Secure Backup Affects Multiple Versions
CVE-2025-21578

6.7MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 April 2025

What is CVE-2025-21578?

A significant security vulnerability exists in Oracle Secure Backup, enabling a high privileged attacker who has logged on to the environment where the software is running to compromise the application. This flaw could allow unauthorized access to sensitive backup data and potentially lead to complete takeover of the Oracle Secure Backup system, raising concerns regarding confidentiality, integrity, and availability of stored information.

Affected Version(s)

Oracle Secure Backup 12.1.0.1

Oracle Secure Backup 12.1.0.2

Oracle Secure Backup 12.1.0.3

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.