Oracle Database Server vulnerabilities
506 known vulnerabilities affecting oracle/database_server.
Total CVEs
506
CISA KEV
0
Public exploits
29
Exploited in wild
0
Severity breakdown
CRITICAL113HIGH73MEDIUM250LOW70
Vulnerabilities
Page 25 of 26
CVE-2012-3146P4LOWCVSS 2.1v10.2.0.3v10.2.0.4+4 more2012-10-16
CVE-2012-3146 [LOW] CVE-2012-3146: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3 allows remote authenticated users to affect integrity via unknown vectors.
nvd
CVE-2020-2517P4LOWCVSS 3.3v11.2.0.4v12.1.0.2+3 more2020-01-15
CVE-2020-2517 [LOW] CVE-2020-2517: Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versio
Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, and 19c. Difficult to exploit vulnerability allows high privileged attacker having Create Procedure, Create Database Link privilege with network access via OracleNet to compromise Database Gateway for ODB
nvd
CVE-2022-21247P4LOWCVSS 2.7v12.2.0.1v19c2022-01-19
CVE-2022-21247 [LOW] CVE-2022-21247: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in
nvd
CVE-2025-50066P4LOWCVSS 2.7≥ 19.3, ≤ 19.27≥ 21.3, ≤ 21.18+1 more2025-07-15
CVE-2025-50066 [LOW] CWE-269 CVE-2025-50066: Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Support
Vulnerability in the Oracle Database Materialized View component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_REDEFINITION privilege with network access via Oracle Net to compromise Oracle Database Material
nvd
CVE-2020-2734P4LOWCVSS 2.4v12.1.0.2v12.2.0.1+2 more2020-04-15
CVE-2020-2734 [LOW] CVE-2020-2734: Vulnerability in the RDBMS/Optimizer component of Oracle Database Server. Supported versions that ar
Vulnerability in the RDBMS/Optimizer component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Execute on DBMS_SQLTUNE privilege with network access via Oracle Net to compromise RDBMS/Optimizer. Successful attacks require human interaction
nvd
CVE-2020-2516P4LOWCVSS 2.4v12.1.0.1v12.1.0.2+2 more2020-01-15
CVE-2020-2516 [LOW] CVE-2020-2516: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Materialized View, Create Table privilege with network access via OracleNet to compromise Core RDBMS. Successful attacks require human interac
nvd
CVE-2009-1969P4LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+3 more2009-07-14
CVE-2009-1969 [LOW] CVE-2009-1969: Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5,
Unspecified vulnerability in the Auditing component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote authenticated users to affect confidentiality via unknown vectors.
nvd
CVE-2010-0901P4LOWCVSS 2.1v9.2.0.8v9.2.0.8dv+4 more2010-07-13
CVE-2010-0901 [LOW] CVE-2010-0901: Unspecified vulnerability in the Export component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1
Unspecified vulnerability in the Export component in Oracle Database Server 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, 11.1.0.7, and 11.2.0.1 allows remote authenticated users to affect confidentiality via unknown vectors related to Select Any Dictionary.
nvd
CVE-2026-34312P4LOWCVSS 2.4≥ 19.3, ≤ 19.302026-04-21
CVE-2026-34312 [LOW] CWE-284 CVE-2026-34312: Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affecte
Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Easily exploitable vulnerability allows high privileged attacker having Row Access Method privilege with network access via multiple protocols to compromise RDBMS. Successful attacks require human interaction from a person other than the
nvd
CVE-2001-1041P4LOWCVSS 2.1v8.0v8.1+1 more2001-08-31
CVE-2001-1041 [LOW] CVE-2001-1041: oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via
oracle program in Oracle 8.0.x, 8.1.x and 9.0.1 allows local users to overwrite arbitrary files via a symlink attack on an Oracle log trace (.trc) file that is created in an alternate home directory identified by the ORACLE_HOME environment variable.
nvd
CVE-2001-0832P4LOWCVSS 2.1≤ 9.0.1v8.0+1 more2001-12-06
CVE-2001-0832 [LOW] CVE-2001-0832: Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files,
Vulnerability in Oracle 8.0.x through 9.0.1 on Unix allows local users to overwrite arbitrary files, possibly via a symlink attack or incorrect file permissions in (1) the ORACLE_HOME/rdbms/log directory or (2) an alternate directory as specified in the ORACLE_HOME environmental variable, aka the "Oracle File Overwrite Security Vulnerability."
nvd
CVE-2012-3151P4LOWCVSS 3.3v10.2.0.4v10.2.0.5+3 more2012-10-16
CVE-2012-3151 [LOW] CVE-2012-3151: Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5,
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.2, and 11.2.0.3, when running on Unix and Linux platforms, allows local users to affect integrity and availability via unknown vectors.
nvd
CVE-2023-22074P4LOWCVSS 2.4≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22074 [LOW] CVE-2023-22074: Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versio
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Select Any Dictionary privilege with network access via Oracle Net to compromise Oracle Database Sharding. Successful attack
nvd
CVE-2025-30750P4LOWCVSS 2.4≥ 19.3, ≤ 19.27≥ 21.3, ≤ 21.18+1 more2025-07-15
CVE-2025-30750 [LOW] CWE-863 CVE-2025-30750: Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.27, 21.3-21.18 and 23.4-23.8. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks require human interaction f
nvd
CVE-2018-2575P4LOWCVSS 2.0v11.2.0.4v12.2.0.12018-01-18
CVE-2018-2575 [LOW] CVE-2018-2575: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with network access via multiple protocols to compromise Core RDBMS. Successful attacks require human interaction from a per
nvd
CVE-2024-20995P4LOWCVSS 2.4≥ 19.3, ≤ 19.22≥ 21.3, ≤ 21.132024-04-16
CVE-2024-20995 [LOW] CWE-404 CVE-2024-20995: Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versio
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.22 and 21.3-21.13. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle Database Sharding. Successful attacks require human interactio
nvd
CVE-2019-2940P4LOWCVSS 2.3v12.1.0.2v12.2.0.1+1 more2019-10-16
CVE-2019-2940 [LOW] CVE-2019-2940: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Create Session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks of this vulnerability can
nvd
CVE-2024-21123P4LOWCVSS 2.3≥ 19.3, ≤ 19.232024-07-16
CVE-2024-21123 [LOW] CWE-276 CVE-2024-21123: Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions t
Vulnerability in the Oracle Database Core component of Oracle Database Server. Supported versions that are affected are 19.3-19.23. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with logon to the infrastructure where Oracle Database Core executes to compromise Oracle Database Core. Successful attacks of this vu
nvd
CVE-2015-4753P4LOWCVSS 2.1v11.2.0.3v11.2.0.4+2 more2015-07-16
CVE-2015-4753 [LOW] CVE-2015-4753: Unspecified vulnerability in the RDBMS Support Tools component in Oracle Database Server 11.2.0.3, 1
Unspecified vulnerability in the RDBMS Support Tools component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality via unknown vectors.
nvd
CVE-2023-22075P4LOWCVSS 2.4≥ 19.3, ≤ 19.20≥ 21.3, ≤ 21.112023-10-17
CVE-2023-22075 [LOW] CVE-2023-22075: Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versio
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Any View, Select Any Table privilege with network access via Oracle Net to compromise Oracle Database Sharding. Succe
nvd