Impact
The flaw exists in the RDBMS component of Oracle Database Server, enabling an unauthenticated attacker with network access via Oracle Net to modify database contents. Unauthorized updates, inserts, or deletions of RDBMS data can occur, directly threatening the integrity of stored information. This weakness is a privilege escalation and authorization bypass (CWE‑284). The description indicates that the impact may extend to additional products beyond the database if the attacker succeeds in changing the scope of the vulnerability.
Affected Systems
Oracle Corporation Oracle Database Server versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2 are affected by this vulnerability.
Risk and Exploitability
The CVSS 3.1 Base Score of 5.8 denotes a medium severity focused on integrity. The EPSS score of less than 1% indicates a very low likelihood of widespread automated exploitation. The vulnerability is not listed in CISA’s KEV catalog. Attackers need only network‑level access to the Oracle Net interface, no authentication, and can exploit the flaw from any remote location that can reach the database server.
OpenCVE Enrichment