Impact
The vulnerability exists in the Config Service Executable of Oracle GoldenGate, which permits an unauthenticated attacker with network access via HTTP to bypass authentication checks. Successful exploitation can provide the attacker with full control over the GoldenGate service, allowing arbitrary configuration changes, data tampering, and complete compromise of the confidentiality, integrity, and availability of all data managed by the system.
Affected Systems
Oracle GoldenGate releases from version 23.4 through 23.26.2 are affected. Any installation of these versions that exposes the Config Service HTTP interface on a reachable network is vulnerable.
Risk and Exploitability
The CVSS v3.1 score of 8.1 indicates a high severity. The EPSS score of less than 1% suggests that active exploitation is currently unlikely, and the vulnerability is not listed in CISA KEV. Attacks would be carried out via network HTTP requests without the need for authentication, but the exploit is described as difficult, so significant skill or access to the target network is required for successful compromise.
OpenCVE Enrichment