Java VM Vulnerability in Oracle Database Server
CVE-2025-61881

5.9MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 October 2025

What is CVE-2025-61881?

A vulnerability in the Java VM component of Oracle Database Server could allow unauthenticated attackers with network access via Oracle Net to compromise the Java VM. This flaw permits unauthorized creation, deletion, or modification of critical data accessible through Java VM. Attackers exploiting this vulnerability might manipulate sensitive data, posing a significant risk to the integrity of the database environment.

Affected Version(s)

Oracle Database Server 19.3 <= 19.28

Oracle Database Server 21.3 <= 21.19

Oracle Database Server 23.4 <= 23.9

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.