Impact
The vulnerability is in the Oracle Database RDBMS component, allowing an attacker with Create Table privileges and network access via Oracle Net to compromise the database server. The flaw is easy to exploit and results in full takeover of the RDBMS, leading to loss of confidentiality, integrity, and availability, as reflected in the CVSS vector. The weakness corresponds to privilege escalation and improper access control.
Affected Systems
Oracle Database Server, versions 23.4.0 through 23.26.3.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity. The EPSS score of less than 1% suggests a low current probability of exploitation, and the vulnerability is not in the CISA KEV list. Because the flaw can be triggered by a low‑privileged account that can create tables over the network through Oracle Net, an attacker can compromise the entire database, gaining full control.
OpenCVE Enrichment