Impact
The vulnerability lies in Oracle's XML Developers Kit component of Oracle Database Server. Attackers who already possess low‑privileged XDKC rights and can reach the system over Oracle Net can exploit this flaw, gaining full control of the XML Developers Kit. Successful exploitation compromises the confidentiality, integrity, and availability of the system because the attacker can take over the component, alter configurations, or disrupt that rely on XML processing.
Affected Systems
Oracle Corporation’s Oracle Database Server, specifically the Oracle XML Developers Kit. Versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3 are affected.
Risk and Exploitability
The CVSS v3.1 base score of 7.5 indicates a high severity, while the EPSS score (<1%) shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers need network access via Oracle Net andC rights to succeed, and the exploit provides full takeover of the XML Developers Kit, impacting all database services that depend on this component.
OpenCVE Enrichment