CVE-2023-21893
Description
Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
Oracle.ManagedDataAccessNuGet | >= 21.0.0, < 21.9.0 | 21.9.0 |
Oracle.ManagedDataAccess.CoreNuGet | >= 3.21.0, < 3.21.90 | 3.21.90 |
Oracle.ManagedDataAccessNuGet | >= 19.0.0, < 19.18.0 | 19.18.0 |
Oracle.ManagedDataAccess.CoreNuGet | >= 2.19.0, < 2.19.180 | 2.19.180 |
Affected products
5cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:oracle:database_server:19c:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:database_server:21c:*:*:*:*:*:*:*
- ghsa-coords2 versions
>= 21.0.0, < 21.9.0+ 1 more
- (no CPE)range: >= 21.0.0, < 21.9.0
- (no CPE)range: >= 3.21.0, < 3.21.90
- Range: 19c
Patches
Vulnerability mechanics
References
5- www.oracle.com/security-alerts/cpujan2023.htmlnvdPatchVendor AdvisoryWEB
- github.com/advisories/GHSA-5pm2-9mr2-3frqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-21893ghsaADVISORY
- www.nuget.org/packages/Oracle.ManagedDataAccess.Core/3.21.90ghsaWEB
- www.nuget.org/packages/Oracle.ManagedDataAccess/21.9.0ghsaWEB
News mentions
0No linked articles in our index yet.