Vulnerability in JDBC Component of Oracle Database Server
CVE-2025-50070

5.3MEDIUM

Key Information:

Vendor

Oracle

Status
Vendor
CVE Published:
15 July 2025

What is CVE-2025-50070?

This vulnerability in the JDBC component of Oracle Database Server affects supported versions 23.4 to 23.8. It presents a challenge for exploitation, as it requires a low privileged attacker with authenticated OS user privileges to access the infrastructure where JDBC operates. Successful exploitation relies on human interaction from someone other than the attacker. Although the vulnerability resides within JDBC, its impact can extend to other products, raising concerns about unauthorized access to sensitive data or even complete access to all JDBC-accessible information.

Affected Version(s)

JDBC 23.4 <= 23.8

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-50070 : Vulnerability in JDBC Component of Oracle Database Server