Unauthorized Data Manipulation in Oracle Database Server's Unified Audit Component
CVE-2023-22034
4.9MEDIUM
Summary
This vulnerability in the Unified Audit component of Oracle Database Server allows a high-privileged attacker with SYSDBA access to potentially compromise the integrity of audit records. With network access via Oracle Net, threats can lead to unauthorized creation, deletion, or modification of critical audit data. The vulnerability affects specific versions of the database server, making it essential for organizations to implement necessary security measures to protect sensitive data from exploitation.
Affected Version(s)
Database - Enterprise Edition 19.3 <= 19.19
Database - Enterprise Edition 21.3 <= 21.10
References
CVSS V3.1
Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved