CVEFinder.io

CVE-2025-53047

đŸ”ļ medium
🔍 Scan for this CVE
Summary

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to

Description

Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Portable Clusterware accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).

CVSS Score
5.8
Medium
EPSS Score
0.0
Exploit Probability
Published Date
2025-10-21
First Seen: 2026-01-05
📊 Relative Risk Intelligence

This CVE is Lower Risk - more severe than 32.7% of all 338,292 vulnerabilities in our database.

#227,662
Below average severity
Severity Percentile
đŸŽ¯ CISA SSVC Assessment Updated: Oct 22, 2025
🔍 Exploitation Status
None
No known exploits
âš™ī¸ Automatable
NO
Requires human interaction
đŸ’Ĩ Technical Impact
Partial
Limited system impact
SSVC data provided by CISA
Last Modified 2025-10-23
CVSS Vector 3.1 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
CWE IDs (Weakness Types)

đŸ“Ļ Affected Products 3

🔗 References 1

🔗 Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-46833 ⛔ critical 9.0 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46834 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-46835 âš ī¸ high 7.5 0.3 Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-2... 2026-05-28
CVE-2026-34312 â„šī¸ low 2.4 0.0 Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.30. Ea... 2026-04-21
CVE-2026-21939 âš ī¸ high 7.0 0.0 Vulnerability in the SQLcl component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.0... 2026-01-20
CVE-2025-53051 â„šī¸ low 2.7 0.0 Vulnerability in the RDBMS Functional Index component of Oracle Database Server. Supported versions that are affected a... 2025-10-21
These CVEs affect the same products