Impact
The flaw in Oracle’s XML Developers Kit allows an attacker who already has low‑privileged XDKC rights and can reach the system over Oracle Net to gain full control of the component. Successful exploitation compromises the confidentiality, integrity, and availability of all database services that rely on XML processing.
Affected Systems
Oracle Database Server, specifically the XML Developers Kit component. Versions 19.3–19.32, 21.3–21.23, and 23.4.0–23.26.3 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates high severity, while the EPSS score of < 1 % shows a very low likelihood of exploitation at present. The vulnerability is not listed in CISA’s KEV catalog. Attackers need network access via Oracle Net and possession of XDKC privileges to succeed, providing them with full takeover of the XML Developers Kit.
OpenCVE Enrichment