Impact
This vulnerability resides in Oracle Database Server’s JDBC component, allowing an unauthenticated attacker with physical access to the host where JDBC runs to potentially compromise data access. Successful exploitation does not provide arbitrary code execution or denial of service, but it grants read or complete access to JDBC‑exposed data, matching the CWE‑284 Authorization Failure weakness and explaining why improper privilege checks lead to confidentiality violations.
Affected Systems
Oracle Database Server JDBC is affected in versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2. These are supported releases and may be used by multiple applications that rely on JDBC connectivity.
Risk and Exploitability
The CVSS base score of 5.6 with an Adjacent Network (AV:A) vector indicates a medium‑to‑low confidentiality risk. The EPSS score is below 1%, showing a very low probability of current exploitation. The flaw requires physical access and a secondary human actor, so attack complexity is high. It is not listed in CISA KEV, but successful exploitation would allow an attacker to read all JDBC‑accessible data, which may be sensitive.
OpenCVE Enrichment