Lucene search

K
nvd[email protected]NVD:CVE-2023-22071
HistoryOct 17, 2023 - 10:15 p.m.

CVE-2023-22071

2023-10-1722:15:12
web.nvd.nist.gov
3
oracle database server
pl/sql
vulnerability
unauthorized access
compromise
network access
denial of service
high privileged attacker
cvss 3.1

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

5.1

Confidence

High

EPSS

0

Percentile

13.3%

Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute on sys.utl_http privilege with network access via Oracle Net to compromise PL/SQL. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PL/SQL, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PL/SQL accessible data as well as unauthorized read access to a subset of PL/SQL accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PL/SQL. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L).

Affected configurations

Nvd
Node
oracledatabase_serverRange19.319.20enterprise
OR
oracledatabase_serverRange21.321.11enterprise
VendorProductVersionCPE
oracledatabase_server*cpe:2.3:a:oracle:database_server:*:*:*:*:enterprise:*:*:*

CVSS3

5.9

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

LOW

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L

AI Score

5.1

Confidence

High

EPSS

0

Percentile

13.3%

Related for NVD:CVE-2023-22071