CVE-2024-20911

V

ulnerability in Oracle Audit Vault and Database Firewall (component: Firewall). Supported versions that are affected are 20.1-20.9. Difficult to exploit vulnerability allows high privileged attacker with network access via Oracle Net to compromise Oracle Audit Vault and Database Firewall. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Audit Vault and Database Firewall, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Audit Vault and Database Firewall accessible data. CVSS 3.1 Base Score 2.6 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:N/A:N).

Configurations

Configuration 1 (hide)

cpe:2.3:a:oracle:audit_vault_and_database_firewall:*:*:*:*:*:*:*:*

History

27 Mar 2025, 18:17

Type Values Removed Values Added
CWE CWE-284

27 Nov 2024, 16:31

Type Values Removed Values Added
CWE NVD-CWE-noinfo
References () https://www.oracle.com/security-alerts/cpujan2024.html - () https://www.oracle.com/security-alerts/cpujan2024.html - Vendor Advisory
CPE cpe:2.3:a:oracle:audit_vault_and_database_firewall:*:*:*:*:*:*:*:*
First Time Oracle
Oracle audit Vault And Database Firewall

21 Nov 2024, 08:53

Type Values Removed Values Added
References () https://www.oracle.com/security-alerts/cpujan2024.html - () https://www.oracle.com/security-alerts/cpujan2024.html -

Information

Published : 2024-02-17 02:15

Updated : 2025-03-27 18:17


NVD link : CVE-2024-20911

Mitre link : CVE-2024-20911

CVE.ORG link : CVE-2024-20911


JSON object : View

CWE
NVD-CWE-noinfo CWE-284

Improper Access Control