Impact
The vulnerability resides in the JDBC component of Oracle Database Server. An attacker with network access via Oracle Net, even without local privileges, can exploit the flaw if a user other than the attacker cooperates. A successful exploitation can fully compromise the JDBC service, resulting in loss of confidentiality, integrity, and availability for the database.
Affected Systems
Oracle Database Server JDBC is affected in all supported versions from 19.3 to 19.31, from 21.3 to 21.22, and from 23.4.0 to 23.26.2. The flaw impacts the JDBC interface that client applications use to connect over the Oracle Net protocol.
Risk and Exploitability
The CVSS 3.1 base score of 6.8 reflects moderate severity but high impact across all core data safety dimensions. The EPSS score is below 1%, and the vulnerability is not listed in CISA KEV, indicating a low probability of exploitation. Still, the requirement for network connectivity and a human interaction from a third party means that the attack window is non‑trivial and a successful attack leads to complete takeover of the JDBC component.
OpenCVE Enrichment