CVE-2024-20909

Vulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Audit Vault and Database Firewall accessible data. CVSS 3.1 Base Score 7.5 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N).
Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:audit_vault_and_database_firewall:*:*:*:*:*:*:*:*

History

27 Nov 2024, 16:32

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://www.oracle.com/security-alerts/cpujan2024.html - () https://www.oracle.com/security-alerts/cpujan2024.html - Vendor Advisory
CPE cpe:2.3:a:oracle:audit_vault_and_database_firewall:*:*:*:*:*:*:*:*
First Time Oracle
Oracle audit Vault And Database Firewall

21 Nov 2024, 08:53

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpujan2024.html - () https://www.oracle.com/security-alerts/cpujan2024.html -

17 Feb 2024, 02:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-17 02:15

Updated : 2024-11-27 16:32


NVD link : CVE-2024-20909

Mitre link : CVE-2024-20909

CVE.ORG link : CVE-2024-20909


JSON object : View

Products Affected

oracle

  • audit_vault_and_database_firewall