CVE-2025-50066Improper Privilege Management in Corporation Oracle Database Server

Severity
2.7LOWNVD
EPSS
0.1%
top 80.88%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15

Description

Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise Oracle Database Materialized View. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database Materia

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages2 packages

NVDoracle/database_server19.319.27+2
CVEListV5oracle_corporation/oracle_database_server19.319.27+2

Patches

🔴Vulnerability Details

2
CVEList
CVE-2025-50066: Vulnerability in the Oracle Database Materialized View component of Oracle Database Server2025-07-15
GHSA
GHSA-93qj-wjm3-vgpc: Vulnerability in the Oracle Database Materialized View component of Oracle Database Server2025-07-15

📋Vendor Advisories

2
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Database Materialized View — CVE-2025-500662025-07-15
Microsoft
mm/mremap: fix move_normal_pmd/retract_page_tables race2024-10-08
CVE-2025-50066 — Improper Privilege Management | cvebase