Java VM Vulnerability in Oracle Database Server
CVE-2023-22052

3.1LOW

Key Information:

Vendor
Oracle
Vendor
CVE Published:
18 July 2023

Summary

This vulnerability resides in the Java VM component of Oracle Database Server, allowing an attacker with low privileges—specifically the Create Session and Create Procedure rights—to potentially exploit the system. By gaining network access through various protocols, an attacker could manipulate data within the Java VM, leading to unauthorized modifications such as updates, insertions, or deletions. The affected versions span Oracle Database Server 19.3 to 19.19 and 21.3 to 21.10, highlighting the importance for users to apply the latest security updates to mitigate risks.

Affected Version(s)

Database - Enterprise Edition 19.3 <= 19.19

Database - Enterprise Edition 21.3 <= 21.10

References

CVSS V3.1

Score:
3.1
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.