Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2023-21893
Published:January 17, 2023
Updated:October 07, 2026
Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform. CVSS 3.1 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H).
Affected Packages
oracle.manageddataaccess (NUGET):
Affected version(s) >=12.2.1100 <12.2.20230118
Fix Suggestion:
Update to version 12.2.20230118
oracle.manageddataaccess (NUGET):
Affected version(s) >=18.3.0 <18.15.1
Fix Suggestion:
Update to version 18.15.1
oracle.manageddataaccess.core (NUGET):
Affected version(s) >=2.12.0-beta2 <2.18.151
Fix Suggestion:
Update to version 2.18.151
oracle.manageddataaccess (NUGET):
Affected version(s) >=21.3.0 <21.9.0
Fix Suggestion:
Update to version 21.9.0
oracle.manageddataaccess.core (NUGET):
Affected version(s) >=3.21.1 <3.21.90
Fix Suggestion:
Update to version 3.21.90
oracle.manageddataaccess (NUGET):
Affected version(s) >=12.1.21 <12.1.24230118
Fix Suggestion:
Update to version 12.1.24230118
oracle.manageddataaccess.core (NUGET):
Affected version(s) >=2.19.3 <2.19.180
Fix Suggestion:
Update to version 2.19.180
oracle.manageddataaccess (NUGET):
Affected version(s) >=19.3.0 <19.18.0
Fix Suggestion:
Update to version 19.18.0
Do you need more information?
Contact Us
CVSS v4
Base Score:
7.7
Attack Vector
NETWORK
Attack Complexity
HIGH
Attack Requirements
NONE
Privileges Required
NONE
User Interaction
PASSIVE
Vulnerable System Confidentiality
HIGH
Vulnerable System Integrity
HIGH
Vulnerable System Availability
HIGH
Subsequent System Confidentiality
NONE
Subsequent System Integrity
NONE
Subsequent System Availability
NONE
CVSS v3
Base Score:
7.5
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH
Weakness Type (CWE)
Improper Access Control
EPSS
Base Score:
0.59