First published: Tue Oct 17 2023(Updated: )
Vulnerability in the Oracle Database Sharding component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Any View, Select Any Table privilege with network access via Oracle Net to compromise Oracle Database Sharding. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database Sharding. CVSS 3.1 Base Score 2.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database Server | >=19.3<=19.20 | |
Oracle Database Server | >=21.3<=21.11 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22075 is a vulnerability in the Oracle Database Sharding component of Oracle Database Server.
Versions 19.3-19.20 and 21.3-21.11 of Oracle Database Server are affected by CVE-2023-22075.
Yes, CVE-2023-22075 is an easily exploitable vulnerability.
An attacker needs to have Create Session, Create Any View, and Select Any Table privileges with network access to exploit CVE-2023-22075.
CVE-2023-22075 has a severity rating of 2.4 (low).