Java VM Vulnerability in Oracle Database Server
CVE-2023-22052
3.1LOW
Summary
This vulnerability resides in the Java VM component of Oracle Database Server, allowing an attacker with low privileges—specifically the Create Session and Create Procedure rights—to potentially exploit the system. By gaining network access through various protocols, an attacker could manipulate data within the Java VM, leading to unauthorized modifications such as updates, insertions, or deletions. The affected versions span Oracle Database Server 19.3 to 19.19 and 21.3 to 21.10, highlighting the importance for users to apply the latest security updates to mitigate risks.
Affected Version(s)
Database - Enterprise Edition 19.3 <= 19.19
Database - Enterprise Edition 21.3 <= 21.10
References
CVSS V3.1
Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved