Vulnerability in Unified Audit Component of Oracle Database Server
CVE-2025-61749

2.7LOW

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-61749?

An access control vulnerability exists in the Unified Audit component of Oracle Database Server, affecting versions 23.4 to 23.9. This flaw allows an attacker with high privileges, specifically those holding DBA credentials and possessing network access via Oracle Net, to manipulate Unified Audit data. Successful exploitation could lead to unauthorized modifications, including updates, inserts, or deletions, impacting the integrity of the data accessible through Unified Audit.

Affected Version(s)

Oracle Database Server 23.4 <= 23.9

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.