CVE-2025-53051

CWE-125Out-of-bounds Read14 documents5 sources
Severity
2.7LOW
EPSS
0.0%
top 91.03%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 21

Description

Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise RDBMS Functional Index. Successful attacks of this vulnerability can result in unauthorized read access to a subset of RDBMS Functional Index accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:NExploitability: 1.2 | Impact: 1.4

Affected Packages2 packages

NVDoracle/database_server23.423.9

🔴Vulnerability Details

12
CVEList
CVE-2025-53051: Vulnerability in the RDBMS Functional Index component of Oracle Database Server2025-10-21
GHSA
GHSA-27cf-pmx7-3wpg: Vulnerability in the RDBMS Functional Index component of Oracle Database Server2025-10-21
OSV
linux-iot vulnerabilities2025-08-04
OSV
linux-azure vulnerabilities2025-07-30
OSV
linux-azure, linux-azure-5.4, linux-azure-fips, linux-raspi, linux-raspi-5.4 vulnerabilities2025-07-29

📋Vendor Advisories

1
Oracle
Oracle Oracle Database Server Risk Matrix: RDBMS Functional Index — CVE-2025-530512025-10-15
CVE-2025-53051 (LOW CVSS 2.7) | Vulnerability in the RDBMS Function | cvebase.io