CVE-2025-21498

CVSS 3.1 Score 5.3 of 10 (medium)

Details

Published Jan 21, 2025

Summary

CVE-2025-21498 is a vulnerability affecting the Oracle HTTP Server component of Oracle Fusion Middleware version 12.2.1.4.0. This issue is classified as easily exploitable and allows unauthenticated attackers to gain unauthorized read access to a subset of Oracle HTTP Server data via HTTP. Successfully exploited attacks can result in confidentiality impacts with a CVSS Base Score of 5.3. The attack requires no user interaction or authentication, making it a potential risk for networks with Oracle HTTP Server exposure.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Oracle Fusion Middleware

Affected Vendors

  • BonqDAO