// For flags

CVE-2016-0450

Oracle GoldenGate Denial of Service Vulnerability

Severity Score

5.0
*CVSS v2

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Unspecified vulnerability in the Oracle GoldenGate component in Oracle GoldenGate 11.2 and 12.1.2 allows remote attackers to affect availability via unknown vectors.

Vulnerabilidad no especificada en el componente Oracle GoldenGate en Oracle GoldenGate 11.2 y 12.1.2 permite a atacantes remotos afectar a la disponibilidad a través de vectores desconocidos.

This vulnerability allows remote attackers to cause a denial condition on vulnerable installations of Oracle GoldenGate. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the GoldenGate mgr process, which listens on TCP port 7809. By default, this process does not require authentication before accepting data delivery and GGSCI commands from a remote machine. This allows for a remote attacker to disable the service or exhaust resources on the target machine.

*Credits: Mike Arnold (Bruk0ut)
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2015-12-09 CVE Reserved
  • 2016-01-21 CVE Published
  • 2024-08-05 CVE Updated
  • 2024-08-05 First Exploit
  • 2024-09-27 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Oracle
Search vendor "Oracle"
Goldengate
Search vendor "Oracle" for product "Goldengate"
11.2
Search vendor "Oracle" for product "Goldengate" and version "11.2"
-
Affected
Oracle
Search vendor "Oracle"
Goldengate
Search vendor "Oracle" for product "Goldengate"
12.1.2
Search vendor "Oracle" for product "Goldengate" and version "12.1.2"
-
Affected