CVE-2025-21578
Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Puntuación base: 6.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.20%
- Percentil entre todas las CVEs puntuadas: 9
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-732
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2025-21578",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2025-21578",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2025-04-17T03:55:21.167093Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "secalert_us@oracle.com",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 6.7,
"attackVector": "LOCAL",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 0.8
}
]
},
"affected": [
{
"source": "secalert_us@oracle.com",
"affectedData": [
{
"vendor": "Oracle Corporation",
"product": "Oracle Secure Backup",
"versions": [
{
"status": "affected",
"version": "12.1.0.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.1.0.2",
"versionType": "semver"
},
{
"status": "affected",
"version": "12.1.0.3",
"versionType": "semver"
},
{
"status": "affected",
"version": "18.1.0.0",
"versionType": "semver"
},
{
"status": "affected",
"version": "18.1.0.1",
"versionType": "semver"
},
{
"status": "affected",
"version": "18.1.0.2",
"versionType": "semver"
}
]
}
]
}
],
"published": "2025-04-15T21:15:48.240",
"references": [
{
"url": "https://www.oracle.com/security-alerts/cpuapr2025.html",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "secalert_us@oracle.com"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-732"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)."
},
{
"lang": "es",
"value": "Vulnerabilidad en Oracle Secure Backup (componente: General). Las versiones compatibles afectadas son 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 y 18.1.0.2. Esta vulnerabilidad, fácilmente explotable, permite a un atacante con privilegios elevados, con acceso a la infraestructura donde se ejecuta Oracle Secure Backup, comprometer Oracle Secure Backup. Los ataques con éxito pueden resultar en la toma de control de Oracle Secure Backup. Puntuación base de CVSS 3.1: 6.7 (impactos en confidencialidad, integridad y disponibilidad). Vector CVSS: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)."
}
],
"lastModified": "2026-06-17T08:43:46.400",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:secure_backup:12.1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2DD2067E-6AF3-4F25-A5E4-BF5EC50AA85F"
},
{
"criteria": "cpe:2.3:a:oracle:secure_backup:12.1.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3249FB1C-25D0-4246-ADE5-61E3E29F93A5"
},
{
"criteria": "cpe:2.3:a:oracle:secure_backup:12.1.0.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6E63770F-B0D5-46B6-BA19-3367B6B9AB0E"
},
{
"criteria": "cpe:2.3:a:oracle:secure_backup:18.1.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5BEBF135-B083-40E2-B0EC-8EAC41666B6D"
},
{
"criteria": "cpe:2.3:a:oracle:secure_backup:18.1.0.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A881F1A8-0D97-4328-B0EF-7021FBE0B0AC"
},
{
"criteria": "cpe:2.3:a:oracle:secure_backup:18.1.0.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A0461D0F-52B6-4E8A-AB65-C175827A43DE"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert_us@oracle.com"
}