Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujul2026.html |
|
Fri, 24 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Unauthenticated Network Access Enables Denial of Service and Unauthorized Data Manipulation in Oracle Database Server RDBMS | |
| Weaknesses | CWE-284 CWE-306 CWE-399 |
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-400 | |
| Metrics |
ssvc
|
Tue, 21 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of RDBMS as well as unauthorized update, insert or delete access to some of RDBMS accessible data. CVSS 3.1 Base Score 8.2 (Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H). | |
| First Time appeared |
Oracle
Oracle database - Rdbms |
|
| CPEs | cpe:2.3:a:oracle:database_-_rdbms:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Oracle
Oracle database - Rdbms |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2026-07-23T15:41:23.105Z
Reserved: 2026-05-18T15:55:10.318Z
Link: CVE-2026-47046
Updated: 2026-07-23T15:41:17.889Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-24T02:15:04Z