Vulnerability in Oracle GoldenGate Affects Multiple Versions
CVE-2022-21551
6.8MEDIUM
Summary
A vulnerability exists in Oracle GoldenGate that allows an attacker with network access to exploit the system through HTTP. This issue affects versions prior to 21.7.0.0.0 for Oracle GoldenGate 21c and 19.1.0.0.220719 for 19c. Successful attacks necessitate human interaction from another user, enabling the attacker to potentially take control of the GoldenGate framework. The impact involves significant risks related to confidentiality, integrity, and overall availability of the system.
Affected Version(s)
GoldenGate 21c: prior to 21.7.0.0.0; 19c: prior to 19.1.0.0.220719
References
CVSS V3.1
Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved