Impact
This vulnerability is a privilege‑assignment flaw (CWE-269) that resides in the RDBMS component of Oracle Database Server. An attacker with low privileges who holds the Create DB Link privilege and can reach the database over Oracle Net can exploit the flaw. Successful exploitation allows the attacker to gain full control of the database server, compromising confidentiality, integrity, and availability of all data stored therein.
Affected Systems
Oracle Corporation’s Oracle Database Server is affected, with supported versions 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3.
Risk and Exploitability
The CVSS base score is 8.8, indicating high severity. The EPSS score is less than 1%, suggesting a low current exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is a network‑based attack through Oracle Net, requiring the Create DB Link privilege on the target system.
OpenCVE Enrichment