CVE-2023-22034: Medium severity oracle database vulnerability
Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 19.3-19.19 and 21.3-21.10. Easily exploitable vulnerability allows high privileged attacker having SYSDBA privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Unified Audit accessible data. CVSS 3.1 Base Score 4.9 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-22034.
What is the title of this vulnerability?
The title of this vulnerability is 'Vulnerability in the Unified Audit component of Oracle Database Server'.
What is the severity of this vulnerability?
The severity of this vulnerability is medium.
What are the affected versions of Oracle Database Server?
The affected versions of Oracle Database Server are 19.3-19.19 and 21.3-21.10.
How can this vulnerability be exploited?
This vulnerability can be exploited by a high privileged attacker with SYSDBA privilege and network access via Oracle Net to compromise Unified Audit.