SCA: security update for Oracle.ManagedDataAccess, Oracle.ManagedDataAccess.Core (GHSA-5pm2-9mr2-3frq)

high Tenable Cloud Security Plugin ID 410959

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Vulnerability in the Oracle Data Provider for .NET component of Oracle Database Server. Supported versions
that are affected are 19c and 21c. Difficult to exploit vulnerability allows unauthenticated attacker with
network access via TCPS to compromise Oracle Data Provider for .NET. Successful attacks require human
interaction from a person other than the attacker. Successful attacks of this vulnerability can result in
takeover of Oracle Data Provider for .NET. Note: Applies also to Database client-only on Windows platform.
(CVE-2023-21893)

See Also

https://github.com/advisories/GHSA-5pm2-9mr2-3frq

Plugin Details

Severity: High

ID: 410959

Version: Revision 1.10

Type: Local

Family: SCA Checks

Published: 1/23/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.6

Temporal Score: 5.6

Vector: CVSS2#AV:N/AC:H/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2023-21893

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 1/18/2023

Vulnerability Publication Date: 1/17/2023

Reference Information

CVE: CVE-2023-21893

cwe: CWE-284