CVE-2025-53051

Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index. Successful attacks of this vulnerability can result in unauthorized read access to a subset of RDBMS Functional Index accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*

History

23 Oct 2025, 16:06

Type Values Removed Values Added
CPE cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*:*
References () https://www.oracle.com/security-alerts/cpuoct2025.html - () https://www.oracle.com/security-alerts/cpuoct2025.html - Vendor Advisory
First Time Oracle database Server
Oracle

22 Oct 2025, 20:15

Type Values Removed Values Added
CWE CWE-125

21 Oct 2025, 20:20

Type Values Removed Values Added
New CVE

Information

Published : 2025-10-21 20:20

Updated : 2025-10-23 16:06


NVD link : CVE-2025-53051

Mitre link : CVE-2025-53051

CVE.ORG link : CVE-2025-53051


JSON object : View

Products Affected

oracle

  • database_server
CWE
CWE-125

Out-of-bounds Read