Impact
A flaw exists in the Oracle Net Services component of Oracle Database Server that permits an unauthenticated attacker to send specially crafted requests over the network. The malicious request triggers uncontrolled resource consumption (CWE‑400), causing the Net Services process to hang or crash, resulting in a full denial of service that renders the database unavailable. Since no credentials or privileged access are required, the vulnerability has a high impact on availability while not directly affecting confidentiality or integrity.
Affected Systems
The vulnerability affects Oracle Database Server, specifically the Net Services component. Supported versions that are vulnerable include 21.3 through 21.23 and 23.4.0 through 23.26.3.
Risk and Exploitability
The CVSS base score of 7.5 indicates a high severity, and the EPSS score of less than 1% suggests that exploitation attempts are currently rare. Although the vulnerability is not listed in the CISA KEV catalog, an unauthenticated attacker with network connectivity to Oracle Net Services can trigger the flaw and cause a continuous denial of service. The flaw is exploitable through unrestricted network access, making it a significant risk for organizations that expose the service without proper access controls.
OpenCVE Enrichment