Impact
The CVE identifies an easily exploitable flaw in the Portable Clusterware component of Oracle Database Server that allows an unauthenticated attacker with network access via HTTP to modify, delete, or create critical data. Successful exploitation can also trigger a hang or crash, resulting in a complete denial of service. The weakness corresponds to improper access control (CWE‑284), enabling attackers to bypass authentication and directly affect system integrity and availability. Because the vulnerability can be triggered remotely without credentials, it provides a straightforward entry point for attackers to compromise clusterware data and stability.
Affected Systems
Oracle Database Server versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 include the vulnerable Portable Clusterware component. The vulnerability is present in all Oracle Database Server deployments using this component.
Risk and Exploitability
The vulnerability has a CVSS v3.1 base score of 9.1, indicating high impact on integrity and availability. The EPSS score of 0.00407 (<1%) suggests a very low exploitation probability, but the high severity and unauthenticated HTTP access still present a risk. The vulnerability is not listed in the CISA KEV catalog, but the CVSS score and unauthenticated HTTP access mean that attackers can reach the target without prior compromise, increasing the risk. Because the attack requires only a network connection to HTTP and no credentials, it is likely to be exploitable from the Internet or internal networks, especially where the Portable Clusterware service is exposed.
OpenCVE Enrichment