Impact
Oracle Corporation's Oracle GoldenGate Admin Server Executable contains a flaw that allows an unauthenticated attacker with physical access to the communication segment attached to the hardware where GoldenGate runs to compromise the application. The vulnerability is an easy‑to‑exploit local issue that can produce a partial denial of service, reducing the availability of the GoldenGate processing engine and disrupting data replication. The weakness is a form of failure to properly manage resources, identified as CWE‑404, indicating insufficient resource handling.
Affected Systems
Oracle Corporation’s Oracle GoldenGate, versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1 are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score of 4.3 indicates a low‑severity availability impact, and the EPSS score of less than 1 % combined with the absence from CISA’s KEV catalogue suggests exploitation is unlikely at present. Because the attack requires local or intra‑segment physical access to the hardware that hosts GoldenGate, the likely attack vector is “Local Access” via the communication segment. No remote exploitation path, integrity, or confidentiality compromise is documented.
OpenCVE Enrichment