Impact
The vulnerability resides in the RDBMS component of Oracle Database Server, permitting a low‑privileged, authenticated user with network connectivity via Oracle Net to compromise the database engine. The flaw is identified as CWE‑269: Privileged Access Management. Successful exploitation can lead to full takeover of the RDBMS, resulting in loss of confidentiality, integrity, and availability for all data stored within the affected instances. The CVSS 3.1 base score of 8.8 reflects high impact across all dimensions and indicates that the flaw is exploitable over the network with relatively low effort.
Affected Systems
Oracle Database Server versions 19.3 through 19.31, 21.3 through 21.22, and 23.4.0 through 23.26.2 are known to be impacted.
Risk and Exploitability
The CVSS score indicates a severe threat, but the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog, indicating no known active exploitation. Attackers would need legitimate, low‑privilege credentials and network access to the Oracle Net listener; no additional prerequisites are disclosed.
OpenCVE Enrichment