Impact
A vulnerability exists in the Oracle Text component of Oracle Database Server that allows a low‑privileged attacker who possesses the Oracle database Create Index privilege to compromise the Oracle Text service over the network. The weakness is a privilege escalation flaw (CWE‑269), giving the attacker elevated control over the service. Successful exploitation can result in complete takeover of Oracle Text, which provides the attacker with full control over the database data and operations. This impacts confidentiality, integrity, and availability and may enable further attacks against other database components and applications, expanding the impact beyond Oracle Text alone.
Affected Systems
Oracle Corporation’s Oracle Database Server is affected. All supported releases in the ranges 19.3‑19.32, 21.3‑21.23, and 23.4.0‑23.26.3 are vulnerable. The database component weakness; other products may be impacted through their use of Oracle Text, expanding the potential attack surface.
Risk and Exploitability
The attacker must first obtain network access to the Oracle Database Server and have Create Index privileges. Once these conditions are met, exploitation can compromise Oracle Text, allowing the attacker to take full control of the service and potentially compromise additional database components. The vulnerability has a CVSS base score of 8.5, indicating high severity, but the EPSS score is less than 1%, indicating a low probability of exploitation. The absence of user interaction simplifies the potential exploitation path.
OpenCVE Enrichment