CVE-2024-20909 is a high-severity vulnerability affecting Oracle Audit Vault and Database Firewall versions 20.1-20.9, specifically within the Firewall component. An unauthenticated attacker can exploit this flaw remotely via Oracle Net, leading to unauthorized creation, deletion, or modification of critical data or all accessible data within the system. With a CVSS 3.1 score of 7.5, this vulnerability presents a significant integrity risk, allowing full data manipulation without user interaction. While no public exploit code or active exploitation has been observed, and community discussion is minimal, the ease of exploitation makes it a notable concern for affected organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 20.1, <= 20.9CPE match | cpe:2.3:a:oracle:audit_vault_and_database_firewall:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.