---
id: CVE-2025-53047
title: Vulnerability in the Portable Clusterware component of Oracle Database Server
summary: >-
  Vulnerability in the Portable Clusterware component of Oracle Database
  Server.  Supported versions that are affected are 19.3-19.28, 21.3-21.19 and 
  23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker
  with network…
severity: medium
cvss: 5.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N'
cwe:
  - CWE-200
vendor: oracle
product: database_server
affected:
  - 'database_server >= 19.3, <= 19.28'
  - 'database_server >= 21.3, <= 21.19'
  - 'database_server >= 23.4, <= 23.9'
published: '2025-10-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T11:10:00.250'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-53047'
references:
  - url: 'https://www.oracle.com/security-alerts/cpuoct2025.html'
    label: secalert_us@oracle.com
tags:
  - nvd
epss: 0.00319
epssPercentile: 0.22814
ingestedAt: '2026-10-08T11:31:27.461Z'
---

## Overview

Vulnerability in the Portable Clusterware component of Oracle Database Server.  Supported versions that are affected are 19.3-19.28, 21.3-21.19 and  23.4-23.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Bonjour to compromise Portable Clusterware.  While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products (scope change).  Successful attacks of this vulnerability can result in  unauthorized read access to a subset of Portable Clusterware accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality impacts).  CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N).

## Affected

- `database_server >= 19.3, <= 19.28`
- `database_server >= 21.3, <= 21.19`
- `database_server >= 23.4, <= 23.9`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
