CVE-2025-50067
9.0Oracle · Application Express
A vulnerability in the Oracle Application Express Strategic Planner Starter App allows a low privileged attacker to achieve a complete system takeover via network-based HTTP interaction.
Executive summary
A critical vulnerability in Oracle Application Express version 24.2.4 and 24.2.5 allows a low privileged attacker to achieve full system takeover through a manipulated HTTP request.
Vulnerability
The flaw resides in the Strategic Planner Starter App component and allows a low privileged attacker with network access to trigger a full system compromise. Successful exploitation requires human interaction and results in a scope change that can impact additional products.
Business impact
The potential for total system takeover poses an extreme risk to organizational data integrity and confidentiality. Given the CVSS base score of 9.0, this vulnerability permits an attacker to gain full control over the Oracle Application Express environment, potentially leading to unauthorized access to sensitive business data and the compromise of integrated systems.
Remediation
Immediate Action: Update Oracle Application Express to the latest secure version as specified in the July 2025 Oracle Security Alert.
Proactive Monitoring: Review web server and application access logs for unusual HTTP requests targeting the Strategic Planner Starter App or anomalous activity originating from low privileged user accounts.
Compensating Controls: Deploy Web Application Firewall (WAF) rules to inspect and filter suspicious traffic patterns targeting the identified application component.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Due to the critical severity rating and the potential for full administrative compromise, administrators must prioritize patching this vulnerability immediately. Ensure all instances of Oracle Application Express are updated to the latest supported versions to eliminate the risk of exploitation.
More Oracle CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Analyst report written
Sources
- Oracle Advisory Vendor advisory