Impact
A vulnerability in the RDBMS component of Oracle Database Server allows an unauthenticated attacker who can reach the database over Oracle Net to compromise the RDBMS. Successful exploitation can lead to a full takeover of the database, providing an attacker control that undermines confidentiality, integrity, and availability.
Affected Systems
The flaw affects Oracle Corporation's Oracle Database Server versions 23.4.0 through 23.26.3. Any deployment of these releases that exposes the Oracle Net service to the network is vulnerable, regardless of other security controls.
Risk and Exploitability
The CVSS 3.1 Base Score of 8.1 indicates high severity. The EPSS score of less than 1% suggests a low likelihood of widespread exploitation, and the vulnerability is not listed in CISA's KEV catalog. However, because the attack requires only network connectivity to Oracle Net and no other preconditions, the practical risk remains significant for exposed environments.
OpenCVE Enrichment