Impact
Vulnerability in Oracle Net Services component of Oracle Database Server allows a network attacker to use TCPS to trigger a hang or crash of the services, resulting in a complete denial of service. Access required no authentication but does require human interaction from a party other than the attacker. The impact is full availability disruption with no known confidentiality or integrity compromise.
Affected Systems
Affected product is Oracle Database Server, specifically the Net Services component, for versions 23.4.0 through 23.26.3.
Risk and Exploitability
The CVSS v3.1 base score is 6.5, reflecting moderate severity primarily due to availability impact. The EPSS score is below 1%, indicating a low probability that the vulnerability will be exploited in the near future. The vulnerability is not listed in CISA’s KEV catalog. An unauthenticated attacker with network connectivity over TCPS can exploit the flaw, but successful attacks also need a second party to provide human interaction. The combination of limited exploitation prerequisites and low EPSS reduces the urgency, but patching remains advisable due to the potential for service disruption.
OpenCVE Enrichment