Impact
A vulnerability in Oracle Database Server’s RDBMS component allows a low‑privileged attacker, possessing Execute on the DBMS_REDEFINITION object, to exploit Oracle Net from the network and compromise the database. The defect yields full control of the RDBMS, enabling confidentiality, integrity, and availability attacks. The CVSS 3.1 Base Score of 8.8 signifies high severity.
Affected Systems
The flaw affects Oracle Corporation’s Oracle Database Server. Supported, vulnerable releases include 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3.
Risk and Exploitability
The vulnerability’s CVSS score of 8.8 reflects a high‑impact scenario, while the EPSS score of less than 1 % suggests a low current exploitation probability. Because the flaw is not listed in the CISA KEV catalog, no public exploits are known as of the last update. Nevertheless, the attack vector—network access via Oracle Net— is reachable by anyone who can reach the database host, and a successful payload would give an attacker unrestricted control over the RDBMS instance.
OpenCVE Enrichment