Impact
The vulnerability is a CWE‑400 resource exhaustion or input validation issue in the Security component of Oracle GoldenGate Stream Analytics 26.1.0.0.0. A low‑privileged user with host login privileges can exploit the flaw to compromise the application, causing a partial denial of service that affects the availability of the software while leaving confidentiality and integrity intact.
Affected Systems
Oracle GoldenGate Stream Analytics version 26.1.0.0.0, provided by Oracle Corporation, is the only product explicitly listed by the CNA as vulnerable. No other versions or variants were identified as affected.
Risk and Exploitability
The CVSS base score of 3.3 indicates low severity, with an availability‑only impact (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L). The EPSS score is less than 1 %, showing a very low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires local low‑privilege access to the host; a remote attacker would need an additional foothold. The partial denial of service could disrupt critical data streams but does not expose or alter data confidentiality or integrity.
OpenCVE Enrichment