Impact
A vulnerability in the Oracle GoldenGate Receiver Service executable permits a low‑privileged attacker with network access via HTTP to cause the service to hang or crash repeatedly, resulting in a complete denial of service. The attack does not expose confidentiality or integrity weaknesses; the primary impact is on availability, as evidenced by the CVSS 3.1 vector indicating an availability impact with no impact to confidentiality or integrity.
Affected Systems
Oracle GoldenGate versions from 19.1.0.0.0 to 19.30.0.0, 21.3 to 21.21, and 23.4 to 23.26.1 are affected. These versions run the Receiver Service component that accepts HTTP connections, and the vulnerability is present only in the specified releases.
Risk and Exploitability
The CVSS Base Score of 6.5 indicates a moderate severity. The EPSS score of less than 1% suggests the probability of exploitation is very low at the time of analysis and it is not listed in the CISA KEV catalog. The likely attack vector is via an external network that can reach the GoldenGate HTTP endpoint; a low privileged attacker does not need elevated system privileges, but does need network connectivity to the Receiver Service.
OpenCVE Enrichment