Impact
The vulnerability in Oracle Database Server’s RDBMS component permits an attacker with high privileges and network access through Oracle Net to perform unauthorized updates, inserts, or deletes on database contents, compromising data integrity.
Affected Systems
Oracle Corporation’s Oracle Database Server is affected in versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2.
Risk and Exploitability
The CVSS v3.1 base score is 2.7, indicating no impact on confidentiality or availability and a low impact on data integrity. The EPSS score is below 1%, showing a very low exploitation probability, and the issue is not listed in the CISA KEV catalog. Attackers would need network connectivity to the database via Oracle Net and elevated privileges to exploit the flaw.
OpenCVE Enrichment