Improper Certificate Validation in Oracle Database Server - CVE-2023-21893
Published: January 17, 2023 / Updated: May 2, 2023
Vulnerability identifier: #VU71244
CSH Severity: Medium
CVSS v4: 7.6 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-21893
CWE-ID: CWE-295
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform MitM attack.
The vulnerability exists due to improper certificate validation within the ValidateRemoteCertificate function in the Oracle ODP.NET managed driver. A remote attacker can perform MitM attack.
Affected software
Oracle Database Server
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
Robotic Process Automation for Cloud Pak
IBM Robotic Process Automation
How to mitigate CVE-2023-21893
Install updates from vendor's website.
Robotic Process Automation for Cloud Pak - addressed in versions 21.0.7.5, 23.0.7
IBM Robotic Process Automation - addressed in versions 21.0.7.5, 23.0.7
IBM Robotic Process Automation - addressed in versions 21.0.7.5, 23.0.7