Impact
The vulnerability resides in Oracle GoldenGate libraries and permits a local user with logon to the infrastructure where GoldenGate runs to perform unauthorized create, update, delete and read operations on data the product can access. This represents a CWE‑284 improper access control weakness. The attacks allow modification of data and reading of sensitive information with low confidentiality and integrity impact.
Affected Systems
Oracle Corporation's Oracle GoldenGate is affected across multiple major releases. Already listed vulnerable version ranges are 19.1.0.0.0 through 19.30.0.0, 21.3 through 21.21, and 23.4 through 23.26.2. No version suffix information is supplied beyond these ranges.
Risk and Exploitability
The CVSS v3.1 base score is 4.4 with a local attack vector, low access complexity, low privilege requirement and no user interaction, reflecting an easier exploitation for a local low‑privileged attacker. The EPSS score is less than 1%, indicating a very low probability of exploitation at the current time, and the vulnerability has not been listed in CISA's KEV catalog. The likely attack path involves a local user gaining privileges to execute GoldenGate processes and leveraging the libraries’ lack of proper access checks to manipulate accessible data.
OpenCVE Enrichment