Impact
Oracle GoldenGate’s Distribution Server executable contains a vulnerability that enables an attacker with network access over HTTPS to execute code with high privileges, potentially leading to a full takeover of the GoldenGate service. The CVSS v3.1 base score of 7.2 reflects significant impacts on confidentiality, integrity, and availability.
Affected Systems
Affected Oracle GoldenGate versions are 21.3 through 21.21 and 23.4 through 23.26.1. Any installation of these releases deployed in an environment where an attacker can reach the HTTPS endpoint is considered vulnerable.
Risk and Exploitability
The vulnerability is considered remotely exploitable, requiring the attacker to send crafted requests over HTTPS. With an EPSS score of less than 1%, real-world exploitation is unlikely at present, and the issue is not listed in the CISA KEV catalog. However, the severe impact makes patching a priority.
OpenCVE Enrichment