CVE-2025-30694

Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 19.3-19.26, 21.3-21.17 and 23.4-23.7. Easily exploitable vulnerability allows low privileged attacker having User Account privilege with network access via HTTP to compromise XML Database. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in XML Database, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of XML Database accessible data as well as unauthorized read access to a subset of XML Database accessible data. CVSS 3.1 Base Score 5.4 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N).
CVSS

No CVSS.

References
Link Resource
https://www.oracle.com/security-alerts/cpuapr2025.html Patch Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:oracle:xml_database:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:xml_database:*:*:*:*:*:*:*:*
cpe:2.3:a:oracle:xml_database:*:*:*:*:*:*:*:*

History

21 Apr 2025, 19:38

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpuapr2025.html - () https://www.oracle.com/security-alerts/cpuapr2025.html - Patch, Vendor Advisory
First Time Oracle
Oracle xml Database
CPE cpe:2.3:a:oracle:xml_database:*:*:*:*:*:*:*:*

16 Apr 2025, 20:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 5.4
v2 : unknown
v3 : unknown

15 Apr 2025, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-15 21:15

Updated : 2025-04-21 19:38


NVD link : CVE-2025-30694

Mitre link : CVE-2025-30694


JSON object : View

Products Affected

oracle

  • xml_database
CWE

No CWE.