PT-2023-1244 · Oracle · Oracle Data Provider For .Net+1

Georg Jung

·

Published

2023-01-17

·

Updated

2024-09-17

·

CVE-2023-21893

CVSS v2.0

7.6

High

VectorAV:N/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Data Provider for .NET versions 19c through 21c
Description The issue is related to insufficient input validation in the Oracle Data Provider for .NET component of Oracle Database Server, allowing an unauthenticated attacker with network access via TCPS to compromise the Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker and can result in the takeover of Oracle Data Provider for .NET. This issue applies to Database client-only on Windows platforms as well.
Recommendations For Oracle Data Provider for .NET versions 19c through 21c, update to a version that includes the fix, as referenced in the readme.txt files inside the .nupkg packages. As a temporary workaround, consider restricting access to the TCPS protocol to minimize the risk of exploitation.

Fix

Improper Access Control

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-00505
CVE-2023-21893
GHSA-5PM2-9MR2-3FRQ
ZDI-23-488

Affected Products

Oracle Data Provider For .Net
Oracle Database