CVE-2025-61749: Low severity Oracle Database Server vulnerability
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 23.4-23.9. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Unified Audit accessible data. CVSS 3.1 Base Score 2.7 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61749?
CVE-2025-61749 is considered to be of high severity due to its exploitable nature by high privileged attackers.
How do I fix CVE-2025-61749?
To mitigate CVE-2025-61749, it's essential to apply the latest security patches provided by Oracle for affected versions of Oracle Database Server.
Who is affected by CVE-2025-61749?
CVE-2025-61749 impacts users of Oracle Database Server versions 23.4 to 23.9 with Unified Audit enabled.
What type of attacks can exploit CVE-2025-61749?
CVE-2025-61749 can be exploited by attackers with DBA privileges who have network access via Oracle Net.
Is CVE-2025-61749 a remote exploit?
Yes, CVE-2025-61749 is a remotely exploitable vulnerability, enabling attackers to compromise Unified Audit through network access.