Skip to content
OracleCVE-2026-47045

Oracle Database Server: open redirect

Medium6.8CVE-2026-47045 · Published Jul 21, 2026 · updated Aug 6, 2026

Vulnerability in the JDBC component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21.3-21.22 and 23.4.0-23.26.2. Easily exploitable vulnerability allows high privileged attacker having None privilege with network access via Oracle Net to compromise JDBC. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of JDBC. CVSS 3.1 Base Score 6.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).

Oracle advisory

Affected versions

PackageAffectedFixed in
Oracle Database Server
Product
>= 19.3, <= 19.31No fix yet
>= 21.3, <= 21.22No fix yet
>= 23.4.0, <= 23.26.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-601

More Oracle advisories

All Oracle
Advisory
Oracle HRMS (US): takeover via Internal Operations
High7.8Jul 21
Oracle HRMS (US): data exposure via Internal Operations
Medium6.5Jul 21
Oracle Work in Process: data tampering via Internal Operations
Medium5.4Jul 21
Oracle HRMS (US): data tampering via US Payroll Year End
High7.1Jul 21
Oracle HRMS (UK): data exposure via UK Payroll
High7.7Jul 21
Oracle Java SE: takeover via Install
High7.8Jul 21

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.