Impact
A flaw in the Java VM component of Oracle Database Server permits an attacker with low‑privilege Create Session rights, coupled with network access via Oracle Net, to exploit insufficient access controls and modify data within the Java VM environment. The vulnerability enables unauthorized creation, deletion, or alteration of data that the Java VM can access, potentially compromising critical or all Java VM‑handled data. This weakness results in an integrity impact without affecting confidentiality or availability.
Affected Systems
Oracle Database Server, Java VM component. Affected releases include Oracle Database Server 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2. Users with network access to the database should ensure proper session authentication and authorization controls are enforced.
Risk and Exploitability
The CVSS 3.1 base score of 6.5 indicates a moderate severity with high impact on integrity. The EPSS score of < 1 % suggests that real‑world exploitation is currently considered unlikely, though not impossible. The vulnerability is not listed in CISA’s KEV catalog, meaning no mass exploitation has been reported yet. The attack vector is inferred to be remote network access: an attacker requires the ability to create a session via Oracle Net and must possess Create Session privileges to trigger the flaw within the Java VM.
OpenCVE Enrichment