Impact
The vulnerability resides in the Oracle Net Services component of Oracle Database Server. It allows an unauthenticated attacker with network access over Oracle Net to cause the service to hang or crash repeatedly, resulting in a complete denial of service. The weakness is a lack of resource consumption controls that can be triggered by crafted input, mapping to the CWE‑400 category of Uncontrolled Resource Consumption.
Affected Systems
Affected products include Oracle Database Server’s Oracle Net Services. Versions impacted are 19.3 through 19.32, 21.3 through 21.23, and 23.4.0 through 23.26.3.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity with a pivotal availability impact. The EPSS score of less than 1 percent reflects a low likelihood of exploitation at present, and the vulnerability is not listed in the CISA KEV catalogue. Exploitation requires only network connectivity to an untrusted Oracle remote host that can contact the database service, making the threat most serious where Oracle Net Services is exposed to untrusted networks. The impact could be system‑wide service outages if the attacker succeeds.
OpenCVE Enrichment