VDB
CISA-2023-21969
CISA-2023-21969
PUBLISHED
CVSS 6.7 MEDIUM
Reported by oracle · Published April 18, 2023
Vulnerability in Oracle SQL Developer (component: Installation). Supported versions that are affected are Prior to 23.1.0. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle SQL Developer executes to compromise Oracle SQL Developer. Successful attacks of this vulnerability can result in takeover of Oracle SQL Developer. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Risk Scores
CVSS 3.1
6.7
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corporation | SQL Developer | * |
| Oracle Corporation | SQL Developer | *, * |
Timeline
- Apr 18, 2023 CVE Published
- Sep 16, 2024 CVE Updated
References
- Oracle Advisory vendor-advisory