Database Integrity Flaw in Oracle Database Server's Materialized View Component
CVE-2025-50066

2.7LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
15 July 2025

What is CVE-2025-50066?

An access control vulnerability in the Materialized View component of Oracle Database Server allows high-privileged attackers, with Execute permissions on DBMS_REDEFINITION, to gain unauthorized access to modify accessible data. This weakness can permit attackers to insert, update, or delete critical data, potentially compromising the integrity of database operations. Supported versions 19.3 to 19.27, 21.3 to 21.18, and 23.4 to 23.8 are at risk, exposing systems to significant data integrity concerns. For further details, refer to the Oracle advisory.

Affected Version(s)

Oracle Database Server 19.3 <= 19.27

Oracle Database Server 21.3 <= 21.18

Oracle Database Server 23.4 <= 23.8

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.