« Volver al listado

CVE-2025-21578

Estado: AnalizadaMedia (6.7)—

Vulnerability in Oracle Secure Backup (component: General). Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and 18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup. Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-21578",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-21578",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-17T03:55:21.167093Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secalert_us@oracle.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "secalert_us@oracle.com",
      "affectedData": [
        {
          "vendor": "Oracle Corporation",
          "product": "Oracle Secure Backup",
          "versions": [
            {
              "status": "affected",
              "version": "12.1.0.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "12.1.0.2",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "12.1.0.3",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "18.1.0.0",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "18.1.0.1",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "18.1.0.2",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-15T21:15:48.240",
  "references": [
    {
      "url": "https://www.oracle.com/security-alerts/cpuapr2025.html",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "secalert_us@oracle.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Vulnerability in Oracle Secure Backup (component: General).  Supported versions that are affected are 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 and  18.1.0.2. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Secure Backup executes to compromise Oracle Secure Backup.  Successful attacks of this vulnerability can result in takeover of Oracle Secure Backup. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts).  CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad en Oracle Secure Backup (componente: General). Las versiones compatibles afectadas son 12.1.0.1, 12.1.0.2, 12.1.0.3, 18.1.0.0, 18.1.0.1 y 18.1.0.2. Esta vulnerabilidad, fácilmente explotable, permite a un atacante con privilegios elevados, con acceso a la infraestructura donde se ejecuta Oracle Secure Backup, comprometer Oracle Secure Backup. Los ataques con éxito pueden resultar en la toma de control de Oracle Secure Backup. Puntuación base de CVSS 3.1: 6.7 (impactos en confidencialidad, integridad y disponibilidad). Vector CVSS: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)."
    }
  ],
  "lastModified": "2026-06-17T08:43:46.400",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:oracle:secure_backup:12.1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2DD2067E-6AF3-4F25-A5E4-BF5EC50AA85F"
            },
            {
              "criteria": "cpe:2.3:a:oracle:secure_backup:12.1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3249FB1C-25D0-4246-ADE5-61E3E29F93A5"
            },
            {
              "criteria": "cpe:2.3:a:oracle:secure_backup:12.1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E63770F-B0D5-46B6-BA19-3367B6B9AB0E"
            },
            {
              "criteria": "cpe:2.3:a:oracle:secure_backup:18.1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5BEBF135-B083-40E2-B0EC-8EAC41666B6D"
            },
            {
              "criteria": "cpe:2.3:a:oracle:secure_backup:18.1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A881F1A8-0D97-4328-B0EF-7021FBE0B0AC"
            },
            {
              "criteria": "cpe:2.3:a:oracle:secure_backup:18.1.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0461D0F-52B6-4E8A-AB65-C175827A43DE"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secalert_us@oracle.com"
}