PT-2023-1244 · Oracle · Oracle Data Provider For .Net+1
Georg Jung
·
Published
2023-01-17
·
Updated
2024-09-17
·
CVE-2023-21893
CVSS v2.0
7.6
High
| Vector | AV:N/AC:H/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Oracle Data Provider for .NET versions 19c through 21c
Description
The issue is related to insufficient input validation in the Oracle Data Provider for .NET component of Oracle Database Server, allowing an unauthenticated attacker with network access via TCPS to compromise the Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker and can result in the takeover of Oracle Data Provider for .NET. This issue applies to Database client-only on Windows platforms as well.
Recommendations
For Oracle Data Provider for .NET versions 19c through 21c, update to a version that includes the fix, as referenced in the readme.txt files inside the
.nupkg packages.
As a temporary workaround, consider restricting access to the TCPS protocol to minimize the risk of exploitation.Fix
Improper Access Control
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Data Provider For .Net
Oracle Database