Description
Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of JDBC. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the JDBC component of Oracle Database Server. An attacker with network access via Oracle Net, even without local privileges, can exploit the flaw if a user other than the attacker cooperates. A successful exploitation can fully compromise the JDBC service, resulting in loss of confidentiality, integrity, and availability for the database.

Affected Systems

Oracle Database Server JDBC is affected in all supported versions from 19.3 to 19.31, from 21.3 to 21.22, and from 23.4.0 to 23.26.2. The flaw impacts the JDBC interface that client applications use to connect over the Oracle Net protocol.

Risk and Exploitability

The CVSS 3.1 base score of 6.8 reflects moderate severity but high impact across all core data safety dimensions. The EPSS score is below 1%, and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation. Still, the requirement for network connectivity and a human interaction from a third party means that the attack window is non‑trivial and a successful attack leads to complete takeover of the JDBC component.

Generated by OpenCVE AI on August 4, 2026 at 05:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle‑provided patch or upgrade to a non‑affected version of the database server.
  • Restrict Oracle Net traffic to the JDBC service so that only trusted hosts and authenticated users can reach it, reducing the attack surface.
  • Enforce strict role‑based access controls on JDBC connections, ensuring users have only the permissions required for their job functions, and audit these rights regularly.

Generated by OpenCVE AI on August 4, 2026 at 05:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 05:30:00 +0000

Type Values Removed Values Added
Title Oracle JDBC Vulnerability Allowing Takeover via Network with User Interaction

Thu, 30 Jul 2026 16:15:00 +0000

Type Values Removed Values Added
Title Oracle JDBC Vulnerability Allowing Takeover via Network with User Interaction

Mon, 27 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title JDBC Component Vulnerability Enabling Database Takeover
Weaknesses CWE-284
CWE-285

Fri, 24 Jul 2026 02:30:00 +0000

Type Values Removed Values Added
Title JDBC Component Vulnerability Enabling Database Takeover
Weaknesses CWE-284
CWE-285

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-601
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
First Time appeared Oracle database Server
Vendors & Products Oracle database Server

Tue, 21 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Description Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of JDBC. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle database - Jdbc
CPEs cpe:2.3:a:oracle:database_-_jdbc:*:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle database - Jdbc
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Oracle Database - Jdbc Database Server
cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-23T15:40:49.299Z

Reserved: 2026-05-18T15:55:10.318Z

Link: CVE-2026-47045

cve-icon Vulnrichment

Updated: 2026-07-23T15:40:34.725Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:17:10.113

Modified: 2026-08-06T13:43:57.967

Link: CVE-2026-47045

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T05:15:03Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')