CVE-2023-21893

HIGH

Oracle Data Provider for .NET <21c - RCE

Title source: llm
STIX 2.1

Description

Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).

References (1)

Core 1
Core References
Patch, Vendor Advisory vendor-advisory
https://www.oracle.com/security-alerts/cpujan2023.html

Scores

CVSS v3 7.5
EPSS 0.0113
EPSS Percentile 78.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-284
Status published
Products (4)
nuget/Oracle.ManagedDataAccess 21.0.0 - 21.9.0NuGet
nuget/Oracle.ManagedDataAccess.Core 3.21.0 - 3.21.90NuGet
oracle/database_server 19c
oracle/database_server 21c
Published Jan 18, 2023
Tracked Since Feb 18, 2026