Impact
The vulnerability exists in the RDBMS component of Oracle Database Server. An unauthenticated attacker with network access to the database via Oracle Net can exploit the flaw to read a subset of data stored in the RDBMS. The impact is primarily a confidentiality breach, allowing attackers to obtain sensitive information without needing credentials. This does not affect integrity or availability.
Affected Systems
Affected versions are Oracle Database Server 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3. Systems running any of these releases without the applicable patch are vulnerable.
Risk and Exploitability
The CVSS 3.1 base score is 5.3, indicating a moderate severity level. The EPSS score is < 1% and the vulnerability is not listed in CISA's KEV catalog. The attack vector operates over the network with Oracle Net, and the vulnerability requires no privileges or user interaction. Although the exploitability is low to moderate, the confidentiality impact makes the risk significant for environments handling sensitive data.
OpenCVE Enrichment