Impact
A vulnerability in the RDBMS component of Oracle Database Server allows a low‑privileged attacker who has the Execute privilege on DBMS_CLOUD to compromise the database server. The flaw permits the attacker to perform arbitrary actions that can result in a full takeover of the RDBMS, causing complete confidentiality, integrity, and availability loss. The CVSS 3.1 Base Score of 9.9 underscores the severity and indicates that the vulnerability can change the scoped impact to affect other Oracle products.
Affected Systems
Oracle Database Server versions 19.3 through 19.31 and 23.4.0 through 23.26.2 are affected. Users of these releases must determine whether they are deployed with the vulnerable component.
Risk and Exploitability
The exploit is readily usable over the network via Oracle Net and requires only the Execute privilege on DBMS_CLOUD. Once accessed, the blast radius extends to the entire database. The EPSS score is less than 1%, indicating a low probability of widespread exploitation, but the high CVSS score and the ability to cause a full takeover make it a top priority for remediation. The vulnerability is not listed in CISA KEV, and the ability to impact additional products may increase its overall risk.
OpenCVE Enrichment