Impact
A vulnerability in the libraries component of Oracle GoldenGate permits an attacker who has logged on with low privileges to the underlying infrastructure to compromise the GoldenGate instance. By exploiting this weakness the attacker can gain full control over the service, resulting in loss of confidentiality, integrity, and availability. The weakness is essentially a local privilege escalation that can evolve into arbitrary code execution, normally categorized as CWE-284 – Improper Access Control.
Affected Systems
This issue affects Oracle GoldenGate products from Oracle Corporation. The specific affected releases are 23.4 through 23.26.1. Users running these versions should verify that they are not using any vulnerable libraries and consider updating to a non‑affected release.
Risk and Exploitability
The CVSS v3.1 base score of 7.8 indicates high severity, but the EPSS score of less than 1% suggests current exploitation likelihood is low, and the vulnerability is not listed in CISA’s KEV catalog. Attack requires the attacker to have some local presence on the host that runs GoldenGate; no user interaction is required and the attack vector is local. If successful, the attacker can reconfigure, replace, or shut down GoldenGate, creating a full compromise of the data replication process.
OpenCVE Enrichment