Impact
The vulnerability resides in the XML Database component of Oracle Database Server. An unauthenticated attacker who can reach the HTTPS interface can potentially retrieve any accessible XML data. The flaw is described as difficult to exploit and requires the involvement of a distinct human actor; however, if successful, it allows unauthorized data access or complete takeover of the XML Database. The weakness primarily impacts confidentiality, as indicated by the high confidentiality impact in the CVSS vector.
Affected Systems
Affected products include Oracle Corporation's Oracle Database Server, specifically the XML Database component. The affected versions are 23.4.0 through 23.26.1. No other versions or products are mentioned. The failure to restrict access pertains only to the XML Database service exposed via HTTPS.
Risk and Exploitability
The CVSS base score of 5.3 places the issue in the medium severity range, with a high confidentiality impact but no integrity or availability impact. The EPSS score is not available, so exploitation likelihood cannot be precisely quantified from the data; the vulnerability is not listed in the CISA KEV catalog. The attack vector is inferred to be remote HTTPS access, and the vulnerability mandates human interaction beyond the attacker, which could lower practical exploitation probability. Nevertheless, the flaw permits unauthorized data access if an attacker overcomes the interaction hurdle.
OpenCVE Enrichment