2.6
CVE-2024-20911
- EPSS 0.18%
- Published 17.02.2024 02:15:46
- Last modified 27.03.2025 18:17:34
- Source secalert_us@oracle.com
- Teams watchlist Login
- Open Login
Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Audit Vault and Database Firewall, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Audit Vault and Database Firewall accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N).
Data is provided by the National Vulnerability Database (NVD)
Oracle ≫ Audit Vault And Database Firewall Version >= 20.1 <= 20.9
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.18% | 0.397 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
secalert_us@oracle.com | 2.6 | 1 | 1.4 |
CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N
|
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.