CVE-2025-21578

Severity
6.7MEDIUM
EPSS
0.1%
top 69.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 15

Description

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts)

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 0.8 | Impact: 5.9

Affected Packages2 packages

NVDoracle/secure_backup6 versions+5

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xx97-cmjp-pm7g: Vulnerability in Oracle Secure Backup (component: General)2025-04-15
CVEList
CVE-2025-21578: Vulnerability in Oracle Secure Backup (component: General)2025-04-15

📋Vendor Advisories

1
Oracle
Oracle Oracle Secure Backup Risk Matrix: General — CVE-2025-215782025-04-15