Impact
Oracle GoldenGate’s Admin Server contains an exploitable flaw that lets a low‑privileged attacker with network access to the HTTP interface read confidential data. The issue is limited to confidentiality, allowing the attacker to retrieve a subset of data that should be protected. The error does not affect integrity or availability; it results in partial data exposure.
Affected Systems
Oracle Corporation’s Oracle GoldenGate product is affected. Versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1 are impacted.
Risk and Exploitability
The CVSS v3.1 score of 4.3 classifies this issue as low severity, reflecting that the only impact is a partial breach of confidentiality. The EPSS score of less than 1% indicates a very low probability that an attacker will exploit this vulnerability, and it is not listed in CISA’s KEV catalog. The likely attack vector is remote, requiring network access to the Admin Server’s HTTP endpoint; the flaw can be exploited by a low‑privileged attacker without the need for credentials or elevated privileges.
OpenCVE Enrichment