PT-2026-44526 · Oracle · Oracle Database Server+1
CVSS v3.1
9.0
Critical
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 23.4.0 through 23.26.2
Description
A flaw in the Net Service component allows an unauthenticated attacker with network access via TLS to compromise the service. Although difficult to exploit, a successful attack can result in a complete takeover of the Net Service and may significantly impact additional products due to a scope change.
Recommendations
Update Oracle Database Server versions 23.4.0 through 23.26.2 to the latest security updates provided by Oracle.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database Server
Database Server