Impact
Oracle GoldenGate Service Manager contains an Improper Access Control flaw (CWE‑284) that permits a low‑privileged adversary with network access over HTTP to compromise the system. Once exploited, an attacker can gain full control of the GoldenGate deployment, leading to complete takeover of the application. The vulnerability is classified as a Remote Code Execution issue, affecting Confidentiality, Integrity, and Availability.
Affected Systems
Oracle GoldenGate versions 19.1.0.0.0 through 19.29.0.0, 21.3 through 21.21, and 23.4 through 23.26.1.0.0 are affected. Users of these releases must confirm their instances fall within these ranges.
Risk and Exploitability
The CVSS base score of 8.8 underscores a high severity threat, with potential for full system compromise. The EPSS score of less than 1% indicates that, as of now, exploitation is not widely observed, and the vulnerability is not catalogued in CISA’s KEV list. Despite low current exploitation probability, the vector is network‑based and requires only an attacker able to reach the HTTP endpoint, making the risk significant for exposed deployments.
OpenCVE Enrichment