Impact
Easily exploitable vulnerability in the JDBC component of Oracle Database Server allows an attacker with network access via Oracle Net to compromise the component and gain the ability to create, delete or modify critical data. This results in an integrity impact as the attacker can alter database contents without authentication, affecting critical or all JDBC accessible data.
Affected Systems
Oracle Database Server, JDBC component, versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2.
Risk and Exploitability
The CVSS v3.1 base score of 6.5 indicates a moderate severity with high integrity impact. The EPSS score of < 1% suggests a very low probability of widespread exploitation at present, and the vulnerability is not listed in CISA’s KEV catalog. Attacks would require unauthenticated network access to Oracle Net, and it is inferred that the attacker may need to convince a human user to interact with malicious JDBC payloads, implying an attacker effort.
OpenCVE Enrichment