Impact
Oracle Database Server contains a vulnerability in its RDBMS component that permits an authenticated low‑privilege user with network access via Oracle Net to trigger a termination of the RDBMS. Because the flaw directly impacts availability, an attacker can repeatedly cause the database to hang or crash, leading to a complete denial of service. The vulnerability is an authentication privilege abuse (CWE‑284) that requires only modest effort to exploit and is described as easily exploitable.
Affected Systems
The issue affects Oracle Database Server releases 23.4.0 through 23.26.3, as identified by the vendor. All installations of those versions that are reachable over Oracle Net and allow authentication with user privileges are at risk. The advisory does not specify platform or operating‑system requirements beyond the database versions.
Risk and Exploitability
Based on the CVSS 3.1 base score of 7.7 and the vector (AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H), the flaw presents a moderate to high impact on availability with a low attacker effort and a local privileged user network requirement. The EPSS score is below 1 %, indicating a very low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Because the flaw can affect other products when in scope, the attack surface expands beyond the RDBMS alone. An attacker would need valid authentication credentials and network access; once authenticated, they can repeatedly issue the failing command until the database crashes.
OpenCVE Enrichment