Impact
Vulnerability in Oracle GoldenGate Library enables a locally privileged user with high privileges and who can log onto the infrastructure where GoldenGate runs to compromise the application. The flaw permits the attacker to read critical data without permission, insert, delete or alter data, and to cause a complete hang or frequent crash that results in denial of service. The weaknesses manifest as improper input validation, improper access control, and a race condition.
Affected Systems
Affected versions of Oracle GoldenGate include 19.1.0.0.0 through 19.30.0.0, 21.3 up to 21.21, and the 23.4 series up to 23.26.2. All releases managed by Oracle Corporation within these ranges are susceptible until a vendor fix is applied.
Risk and Exploitability
The CVSS Base Score of 5.8 indicates moderate impact, with confidentiality and availability rated high and integrity rated low. EPSS is less than 1 %, and the vulnerability is not listed in CISA’s KEV. The attack vector is local, requiring high privileged access and user interaction, limiting exploitation to users who can log in locally. While exploitation may be difficult, the potential damage—including unauthorized data modification and repeated service outages—represents a significant risk for environments handling sensitive data.
OpenCVE Enrichment