Impact
A vulnerability exists in the RDBMS component of Oracle Database Server that allows a low‑privileged authenticated user with network access via Oracle Net to compromise the database management system. Successful exploitation can result in full takeover of the RDBMS, potentially affecting confidentiality, integrity, and availability, and may extend to other products that depend on the RDBMS, indicating a scope change.
Affected Systems
Oracle Corporation’s Oracle Database Server, specifically the supported versions identified as 23.4.0 through 23.26.3.
Risk and Exploitability
The vulnerability carries a CVSS 3.1 base score of 8.5, reflecting high confidentiality, integrity, and availability impact. EPSS score is less than 1%, and the vulnerability is not listed in CISA’s KEV catalog, but the attack vector is remote over the network for authenticated users. Because the attacker only needs low‑privilege authentication, the risk of exploitation is significant, and the potential for system‑wide compromise warrants immediate attention.
OpenCVE Enrichment