Oracle Database Server
cpe:2.3:a:oracle:database_server:*:*:*:*:*:*:*
- >= 19.3, <= 19.27
- >= 21.3, <= 21.18
A vulnerability has been identified in the Java VM component of Oracle Database Server, affecting versions 19.3 through 19.27 and 21.3 through 21.18. This easily exploitable vulnerability allows a low-privileged attacker with Create Session and Create Procedure privileges, and network access via Oracle Net, to compromise the Java VM. While the vulnerability resides in the Java VM, successful exploitation could significantly impact additional products, leading to a scope change. Attacks exploiting this vulnerability could result in unauthorized access to critical data or complete access to all data accessible by the Java VM.
Exploitation of this vulnerability could lead to unauthorized access to critical data or complete access to all data accessible by the Java VM.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.