← Vulnerability feed

Vulnerability record · CVE-2025-50067 · published 15 July 2025

CVE-2025-50067: Oracle application express open redirect vulnerability

Oracle · Application Express

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Express. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).

9.0 CVSS 3.1 Critical EPSS 0.29% · top 80.3% CWE-601 · Open redirect
9.0CVSS 3.1 base score
0.29%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Vulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Application Express. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Application Express, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Application Express. CVSS 3.1 Base Score 9.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H).

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-50067 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed10.0CVE-2008-1822Oracle application express vulnerabilityUnspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vector…EPSS 2.1%9.0CVE-2023-21974Oracle application express vulnerabilityVulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions tha…EPSS 0.61%9.0CVE-2023-21975Oracle application express vulnerabilityVulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that ar…EPSS 0.61%7.5CVE-2022-24729Ckeditor uncontrolled resource consumption vulnerabilityCKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plug…EPSS 2.4%7.5CVE-2020-7760Codemirror uncontrolled resource consumption vulnerabilityThis affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expressio…EPSS 5.3%6.5CVE-2021-32723Prismjs prism uncontrolled resource consumption vulnerabilityPrism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is us…EPSS 1.4%6.5CVE-2021-26271Ckeditor inclusion from untrusted sphere vulnerabilityIt was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of sp…EPSS 2.0%

Source: NIST National Vulnerability Database (record CVE-2025-50067), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.