Impact
The vulnerability resides in Oracle GoldenGate’s Admin Server Executable and allows a low‑privileged attacker who can reach the system over HTTPS to compromise the GoldenGate instance. This is due to an access control weakness (CWE‑284) that permits privilege escalation. Successful exploitation results in full takeover, impacting confidentiality, integrity, and availability. The CVSS 3.1 base score of 8.8 reflects these wide‑ranging effects.
Affected Systems
Oracle GoldenGate products, specifically versions 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.1. The vulnerability applies to all builds that include the Admin Server component.
Risk and Exploitability
With a network‑reachable HTTPS interface and a relatively low attack complexity, the exploit is likely feasible for attackers who can exercise even low‑privileged access. The EPSS score is less than 1 %, indicating that, while exploitation is possible, it remains uncommon. The vulnerability is not listed in the CISA KEV catalog, but the high CVSS score and the critical functional impact warrant urgent attention.
OpenCVE Enrichment