Oracle Database Server
cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*
- >= 19.3, <= 19.25
- >= 21.3, <= 21.16
- >= 23.4, <= 23.6
A vulnerability has been identified in the Java VM component of Oracle Database Server. It affects versions 19.3 through 19.25, 21.3 through 21.16, and 23.4 through 23.6. This vulnerability is difficult to exploit but allows a low-privileged attacker with Create Session and Create Procedure privileges, and network access via Oracle Net, to compromise the Java VM. Successful exploitation could lead to unauthorized modification, addition, or deletion of certain Java VM accessible data, as well as unauthorized reading of a subset of that data.
Exploitation of this vulnerability could result in unauthorized access to modify, insert, or delete some data accessible to the Java VM, as well as unauthorized reading of certain Java VM accessible data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.