Unauthenticated Access Vulnerability in Oracle Notification Server Component of Oracle Database
CVE-2023-22073

4.3MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

A vulnerability exists in the Oracle Notification Server component of Oracle Database Server that allows unauthenticated attackers with access to the physical communication segment to compromise the server. This vulnerability can lead to unauthorized read access to certain data within the Oracle Notification Server. The affected versions of Oracle Database Server include those from 19.3 to 19.20 and 21.3 to 21.11. Organizations are urged to assess their deployment and apply necessary security measures to mitigate potential data breaches.

Affected Version(s)

Database - Enterprise Edition 19.3 <= 19.20

Database - Enterprise Edition 21.3 <= 21.11

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.