Impact
Portable Clusterware, a component of Oracle Database Server, contains an easily exploitable flaw that allows an unauthenticated attacker with access to the physical communication segment attached to the hardware to compromise the clusterware. Exploitation can lead to full takeover of Portable Clusterware, affecting confidentiality, integrity, and availability. The flaw can alter the scope of the affected system, potentially compromising additional Oracle products during an attack.
Affected Systems
Oracle Database Server versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 are affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS 3.1 base score of 9.6 indicates a severe vulnerability. By aligning with the CVSS vector AV:A, it is inferred that the attack requires physical proximity to the hardware. The EPSS score of less than 1 percent points to a very low probability of exploitation in the current landscape. The vulnerability is not listed in CISA's KEV catalog. Based on the scope change noted in the description, it is inferred that additional Oracle products that depend on Portable Clusterware could also be affected if the vulnerability is successfully exploited. These factors together underscore the need for urgent attention from impacted organizations.
OpenCVE Enrichment