First published: Tue Jan 16 2024(Updated: )
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. While the vulnerability is in Oracle Audit Vault and Database Firewall, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Audit Vault and Database Firewall accessible data. CVSS 3.1 Base Score 3.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Audit Vault | >=20.1<=20.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-20910 is considered a high-severity vulnerability due to its potential for exploitation by high-privileged attackers.
CVE-2024-20910 affects users of Oracle Audit Vault and Database Firewall versions 20.1 to 20.9.
To mitigate CVE-2024-20910, users should apply the latest security patches provided by Oracle for affected versions.
CVE-2024-20910 is categorized as a difficult to exploit vulnerability that allows network access via Oracle Net.
CVE-2024-20910 specifically impacts the Firewall component of Oracle Audit Vault and Database Firewall.