Impact
A low‑privileged attacker who can reach Oracle GoldenGate Microservices over HTTP can exploit an easily‑exploitable vulnerability that allows complete takeover of the GoldenGate instance. The flaw provides full confidentiality, integrity, and availability compromise, effectively granting the attacker unrestricted control over the system.
Affected Systems
Oracle GoldenGate Microservices is the affected component. The vulnerability impacts the following version ranges: 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1. Any installation of these versions is at risk and should be verified against the affected list.
Risk and Exploitability
The CVSS v3.1 base score of 8.8 indicates high severity; the EPSS score of less than 1 % suggests a low probability of exploitation in the general population, yet the impact of a successful attack is severe. The vulnerability is not yet listed in the CISA KEV catalog. The likely attack vector is a remote HTTP request sent from a low‑privileged network user, with the attacker potentially providing crafted input that the service processes without adequate validation. Given the high impact scores, the risk remains significant for any systems still running the affected versions and should not be ignored.
OpenCVE Enrichment