Vulnerability in JDBC Component of Oracle Database Server
CVE-2026-47045

6.8MEDIUM

Key Information:

Vendor

Oracle

Vendor
CVE Published:
21 July 2026

What is CVE-2026-47045?

A security flaw in the JDBC component of Oracle Database Server may allow an attacker with network access to exploit this vulnerability. While the attacker requires elevated privileges, human interaction from a non-attacker is necessary for successful exploitation. Compromised JDBC could lead to unauthorized access and complete control of database interactions, significantly impacting confidentiality, integrity, and availability.

Affected Version(s)

Oracle Database Server 19.3 <= 19.31

Oracle Database Server 21.3 <= 21.22

Oracle Database Server 23.4.0 <= 23.26.2

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.