Impact
The vulnerability resides in the Portable Clusterware component of Oracle Database Server, enabling an unauthenticated attacker who has access to the physical communication segment attached to the hardware where the Portable Clusterware runs to compromise the clusterware. If successfully exploited the attacker can take over Portable Clusterware, resulting in the compromise of confidentiality, integrity, and availability of the affected database environment. The weakness involves improper access control that allows local physical attackers to gain privileged control over the clusterware services.
Affected Systems
Affected are Oracle Corporation’s Oracle Database Server products. Specifically, Portable Clusterware versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 are vulnerable. The cited advisory indicates that successful exploitation could also impact additional Oracle products beyond Portable Clusterware, expanding the potential scope of impact.
Risk and Exploitability
The CVSS v3.1 base score is 9.6 with an Availability Impact and a Confidentiality, Integrity, and Availability compromise. The attack vector is AV:A—adjacent local—meaning the attacker must have physical or local network access to the communication segment. EPSS score of < 1% indicates a very low probability of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog, indicating it has not yet been observed in the wild but could be high severity if an exploited code path is triggered. The nature of the flaw implies a likely exploitation path that requires physical proximity or control over the local network segment, but once that condition is met, the attacker can achieve full control of the Portable Clusterware services.
OpenCVE Enrichment