CVE-2023-22073

4 documents4 sources
Severity
4.3MEDIUM
EPSS
0.1%
top 79.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 17
Latest updateOct 18

Description

Vulnerability in the Oracle Notification Server component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Notification Server executes to compromise Oracle Notification Server. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Notification Serv

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages2 packages

NVDoracle/database_server19.319.20+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qmhg-c8c8-6m24: Vulnerability in the Oracle Notification Server component of Oracle Database Server2023-10-18
CVEList
CVE-2023-22073: Vulnerability in the Oracle Notification Server component of Oracle Database Server2023-10-17

📋Vendor Advisories

1
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle Notification Server — CVE-2023-220732023-10-15