CVE-2022-21432

LOW

Oracle Database 12.1.0.2, 19c, 21c - Authenticated Partial Denial of Service via Oracle Net

Title source: llm
STIX 2.1

Description

Vulnerability in the Oracle Database - Enterprise Edition RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition RDBMS Security. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Database - Enterprise Edition RDBMS Security. CVSS 3.1 Base Score 2.7 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L).

References (1)

Core 1
Core References

Scores

CVSS v3 2.7
EPSS 0.0013
EPSS Percentile 31.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

Status published
Products (3)
oracle/database 12.1.0.2
oracle/database 19c
oracle/database 21c
Published Jul 19, 2022
Tracked Since Feb 18, 2026