Vulnerability in Oracle Database Recovery Manager Affects Oracle Database Server
CVE-2023-22077

4.9MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2023

Summary

The vulnerability in Oracle Database Recovery Manager poses a significant risk, enabling an attacker with DBA privileges and network access via Oracle Net to exploit the system. This exploitation could lead to unauthorized operations, including causing the Recovery Manager to hang or repeatedly crash, resulting in denial of service. Affected versions of the Oracle Database Server, specifically from 19.3 to 19.20 and 21.3 to 21.11, require urgent attention to mitigate these risks.

Affected Version(s)

Database - Enterprise Edition 19.3 <= 19.20

Database - Enterprise Edition 21.3 <= 21.11

References

CVSS V3.1

Score:
4.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.