Impact
The vulnerability allows an unauthenticated attacker with network access to the Oracle Net interface to cause a complete denial of service by repeatedly crashing the RDBMS. The flaw is classified as a resource exhaustion weakness (CWE-400). It also grants the attacker unauthorized ability to update, insert, or delete data that the RDBMS can access. The described impact spans both availability and integrity, as reflected in its CVSS vector (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H).
Affected Systems
Oracle Database Server, specifically supported releases from 23.4.0 through 23.26.2. These versions lack the necessary authentication checks for incoming Oracle Net connections, enabling the exploitation path described.
Risk and Exploitability
With a CVSS Base Score of 8.2 and an EPSS score below 1 %, exploitation is considered unlikely but not impossible. The vulnerability is not currently listed in the CISA KEV catalog, but the attack vector is a straightforward network‑based access to Oracle Net without authentication. Successful exploitation grants the attacker both denial of service and the ability to manipulate database records.
OpenCVE Enrichment