cbcvebase.

Oracle Database Server vulnerabilities

506 known vulnerabilities affecting oracle/database_server.

Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70

Vulnerabilities

Page 18 of 26
CVE-2025-50070P4MEDIUMCVSS 5.3≥ 23.4, ≤ 23.82025-07-15
CVE-2025-50070 [MEDIUM] CWE-284 CVE-2025-50070: Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 23.4-23.8. Difficult to exploit vulnerability allows low privileged attacker having Authenticated OS User privilege with logon to the infrastructure where JDBC executes to compromise JDBC. Successful attacks require human interaction from a person
nvd
CVE-2012-1708P4MEDIUMCVSS 4.3v4.0v4.12012-05-03
CVE-2012-1708 [MEDIUM] CVE-2012-1708: Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1 Unspecified vulnerability in the Application Express component in Oracle Database Server 4.0 and 4.1 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2012-0525P4MEDIUMCVSS 4.9v11.1.0.7v11.2.0.2+1 more2012-05-03
CVE-2012-0525 [MEDIUM] CVE-2012-0525: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5 and 11.1.0.1, allows remote authenticated users to affect confidentiality and integrity via unknown vectors related to Enterprise Config Management.
nvd
CVE-2021-1993P4MEDIUMCVSS 4.8v12.1.0.2v12.2.0.1+2 more2021-01-20
CVE-2021-1993 [MEDIUM] CVE-2021-1993: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other
nvd
CVE-2004-1338P4MEDIUMCVSS 6.5v10.2.12004-12-23
CVE-2004-1338 [MEDIUM] CWE-264 CVE-2004-1338: The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partia The triggers in Oracle 9i and 10g allow local users to gain privileges by using a sequence of partially privileged actions: using CCBKAPPLROWTRIG or EXEC_CBK_FN_DML to add arbitrary functions to the SDO_CMT_DBK_FN_TABLE and SDO_CMT_CBK_DML_TABLE, then performing a DELETE on the SDO_TXN_IDX_INSERTS table, which causes the SDO_CMT_CBK_TRIG trigger to ex
nvd
CVE-2009-1965P4MEDIUMCVSS 5.4v9.2.0.8v10.1.0.52009-10-22
CVE-2009-1965 [MEDIUM] CVE-2009-1965: Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1. Unspecified vulnerability in the Net Foundation Layer component in Oracle Database 9.2.0.8 and 10.1.0.5 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2023-22077P4MEDIUMCVSS 4.9≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22077 [MEDIUM] CVE-2023-22077: Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supporte Vulnerability in the Oracle Database Recovery Manager component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having DBA account privilege with network access via Oracle Net to compromise Oracle Database Recovery Manager. Successful attacks of th
nvd
CVE-2012-0527P4MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0527 [MEDIUM] CVE-2012-0527: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5, allows remote attackers to affect integrity via unknown vectors related to Schema Management, a different vulnerability than CVE-2012-0526.
nvd
CVE-2012-0526P4MEDIUMCVSS 4.3v10.2.0.3v10.2.0.4+4 more2012-05-03
CVE-2012-0526 [MEDIUM] CVE-2012-0526: Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Serve Unspecified vulnerability in the Enterprise Manager Base Platform component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, and Oracle Enterprise Manager Grid Control 10.2.0.5, allows remote attackers to affect integrity via unknown vectors related to Schema Management, a different vulnerability than CVE-2012-0527.
nvd
CVE-2015-2586P4MEDIUMCVSS 4.3≤ 4.2.02015-07-16
CVE-2015-2586 [MEDIUM] CVE-2015-2586: Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2. Unspecified vulnerability in the Application Express component in Oracle Database Server before 4.2.1 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2011-2231P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.3+4 more2011-07-20
CVE-2011-2231 [MEDIUM] CVE-2011-2231: Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10. Unspecified vulnerability in the XML Developer Kit component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, and 11.2.0.1, Oracle Fusion Middleware 10.1.3.5, allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2010-2407P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.4+1 more2010-10-14
CVE-2010-2407 [MEDIUM] CVE-2010-2407: Unspecified vulnerability in the XDK component in Oracle Database Server 10.1.0.5, 10.2.0.4, and 11. Unspecified vulnerability in the XDK component in Oracle Database Server 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2011-0879P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-0879 [MEDIUM] CVE-2011-0879: Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 1 Unspecified vulnerability in the Instance Management component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect integrity via unknown vectors.
nvd
CVE-2011-0876P4MEDIUMCVSS 4.3v10.1.0.5v10.2.0.3+5 more2011-07-20
CVE-2011-0876 [MEDIUM] CVE-2011-0876: Unspecified vulnerability in the Enterprise Manager Console component in Oracle Database Server 10.1 Unspecified vulnerability in the Enterprise Manager Console component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Oracle Enterprise Manager Grid Control 10.1.0.6 and 10.2.0.5; allows remote attackers to affect integrity via unknown vectors related to Security.
nvd
CVE-2007-5513P4MEDIUMCVSS 5.0v9.2.0.8v9.2.0.8dv+1 more2007-10-17
CVE-2007-5513 [MEDIUM] CVE-2007-5513: The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect The XML DB (XMLDB) component in Oracle Database 9.2.0.8, 9.2.0.8DV, and 10.1.0.5 generates incorrect audit entries in the USERID column in which (1) long usernames are trimmed to 5 characters, or (2) short entries contain any extra characters from usernames in previous entries, aka DB23.
nvd
CVE-2001-0943P4HIGHCVSS 7.2v8.0.5v8.1.52001-08-31
CVE-2001-0943 [HIGH] CVE-2001-0943: dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to dbsnmp in Oracle 8.0.5 and 8.1.5, under certain conditions, trusts the PATH environment variable to find and execute the (1) chown or (2) chgrp commands, which allows local users to execute arbitrary code by modifying the PATH to point to Trojan Horse programs.
nvd
CVE-2009-3414P4MEDIUMCVSS 4.9v9.2.0.8v9.2.0.8dv+2 more2010-01-13
CVE-2009-3414 [MEDIUM] CVE-2009-3414: Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10. Unspecified vulnerability in the Oracle Spatial component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2008-3976 and CVE-2009-3413.
nvd
CVE-2009-3411P4MEDIUMCVSS 4.9v9.2.0.8v9.2.0.8dv+4 more2010-01-13
CVE-2009-3411 [MEDIUM] CVE-2009-3411: Unspecified vulnerability in the Oracle Data Pump component in Oracle Database 11.1.0.7, 10.2.0.3, 1 Unspecified vulnerability in the Oracle Data Pump component in Oracle Database 11.1.0.7, 10.2.0.3, 10.2.0.4, 10.1.0.5, 9.2.0.8, and 9.2.0.8DV allows remote authenticated users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2015-0371P4MEDIUMCVSS 4.9v11.1.0.7v11.2.0.3+2 more2015-01-21
CVE-2015-0371 [MEDIUM] CVE-2015-0371: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect integrity and availability via unknown vectors.
nvd
CVE-2010-2411P4MEDIUMCVSS 4.6v10.1.0.5v10.2.0.3+3 more2010-10-14
CVE-2010-2411 [MEDIUM] CVE-2010-2411: Unspecified vulnerability in the Job Queue component in Oracle Database Server 11.2.0.1, 11.1.0.7, 1 Unspecified vulnerability in the Job Queue component in Oracle Database Server 11.2.0.1, 11.1.0.7, 10.2.0.3, 10.2.0.4, and 10.1.0.5 allows remote authenticated users to affect confidentiality, integrity, and availability, related to SYS.DBMS_IJOB.
nvd
Oracle Database Server vulnerabilities | cvebase