
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability in Oracle SQL Developer's Installation component (CVE-2023-21969) affects versions prior to 23.1.0. The vulnerability was discovered by Emad Al-Mousa of Saudi Aramco and disclosed in April 2023 (Oracle CPU).
The vulnerability is easily exploitable and requires a high-privileged attacker with logon access to the infrastructure where Oracle SQL Developer executes. It has been assigned a CVSS 3.1 Base Score of 6.7 (Medium) with the vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, indicating local access, low attack complexity, high privileges required, no user interaction, unchanged scope, and high impacts on confidentiality, integrity, and availability (NVD).
Successful exploitation of this vulnerability can result in complete takeover of Oracle SQL Developer, potentially compromising the confidentiality, integrity, and availability of the system (Oracle CPU).
The vulnerability is characterized as easily exploitable but requires high privileges and local access to the infrastructure where Oracle SQL Developer executes. The attacker must have logon access to the target system (NVD).
Oracle has addressed this vulnerability in version 23.1.0 of SQL Developer. Users are strongly recommended to upgrade to this version or later to mitigate the risk (Oracle CPU).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."