Impact
This vulnerability resides in the Oracle GoldenGate Admin Server Executable and allows an unauthenticated attacker who can reach the system over HTTPS to read a subset of data exposed by the GoldenGate instance. The vulnerability is classified as a medium‑severity flaw with a CVSS v3.1 Base Score of 5.3 that reflects a Confidentiality impact only. Because integrity and availability are not affected, the compromise is limited to data leakage.
Affected Systems
Oracle GoldenGate products version 21.3 through 21.21 and 23.4 through 23.26.1 are affected. Any installation of these releases with an exposed Admin Server is vulnerable until a vendor-supplied patch is applied.
Risk and Exploitability
The flaw can be exploited remotely over the network without authentication, making it accessible to any machine that can reach the Admin Server via HTTPS. The EPSS score of less than 1% indicates a low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. An attacker can gain read-only access to sensitive GoldenGate data, potentially exposing confidential information. Prompt patching or mitigation is recommended to eliminate this risk.
OpenCVE Enrichment