CVE-2025-21578

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
References
Link Resource
https://www.oracle.com/security-alerts/cpuapr2025.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:secure_backup:12.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:12.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:12.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.2:*:*:*:*:*:*:*

History

17 Apr 2025, 21:37

Type Values Removed Values Added
First Time Oracle
Oracle secure Backup
References () https://www.oracle.com/security-alerts/cpuapr2025.html - () https://www.oracle.com/security-alerts/cpuapr2025.html - Patch, Vendor Advisory
CPE cpe:2.3:a:oracle:secure_backup:12.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:12.1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.0:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:12.1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:oracle:secure_backup:18.1.0.1:*:*:*:*:*:*:*

16 Apr 2025, 21:15

Type Values Removed Values Added
CWE CWE-732

16 Apr 2025, 13:25

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad en Oracle Secure Backup (componente: General). Las versiones compatibles afectadas son 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 y 18.1.0.2. Esta vulnerabilidad, fácilmente explotable, permite a un atacante con privilegios elevados, con acceso a la infraestructura donde se ejecuta Oracle Secure Backup, comprometer Oracle Secure Backup. Los ataques con éxito pueden resultar en la toma de control de Oracle Secure Backup. Puntuación base de CVSS 3.1: 6.7 (impactos en confidencialidad, integridad y disponibilidad). Vector CVSS: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

15 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 21:15

Updated : 2025-04-17 21:37


NVD link : CVE-2025-21578

Mitre link : CVE-2025-21578

CVE.ORG link : CVE-2025-21578


JSON object : View

Products Affected

oracle

  • secure_backup
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource