LiveActive security incident?Get immediate response
CVE Record

CVE-2022-21511: Vulnerability in the Oracle Database - Enterprise Edition Recovery component of Oracle Database Server.

Vulnerability in the Oracle Database - Enterprise Edition Recovery component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows high privileged attacker having EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Recovery. Successful attacks of this vulnerability can result in takeover of Oracle Database - Enterprise Edition Recovery. Note: None of the supported versions are affected. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

HighCVSS 7.2Not KEV-listedUpdated
Glexia's TakeAutomated analysishigh

Security readout for executives and security teams

Plain-English summary

This CVE describes a high-impact Oracle Database Enterprise Edition Recovery issue, but Oracle’s record states none of the supported versions are affected. An attacker would already need a powerful database privilege and Oracle Net access. Treat it as a verification item for Oracle Database inventories, especially legacy or unsupported deployments.

Executive priority

Prioritize confirmation over emergency response. The potential impact is high, but the provided evidence says no supported versions are affected and gives no active-exploitation signal. Unsupported Oracle databases deserve faster review.

Technical view

CVE-2022-21511 affects the Oracle Database Enterprise Edition Recovery component. The described path requires network access via Oracle Net and the EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT privilege. Successful exploitation could compromise the Recovery component with high confidentiality, integrity, and availability impact. The CVE record lists CVSS 7.2 and notes no supported versions are affected.

Likely exposure

Likely exposure appears limited. The source bundle lists affected versions as “None” and states no supported versions are affected. Organizations should still verify Oracle Database Enterprise Edition assets, especially unsupported, legacy, or unpatched systems.

Exploitation context

No provided source says this CVE is actively exploited, and it is not listed as KEV in the source bundle. The attacker model is privileged: the attacker needs Oracle Net access and a specific EXECUTE privilege before compromise is possible.

Researcher notes

The useful validation angle is privilege and reachability, not exploit reproduction. Source evidence is sparse: no CWE, no affected supported versions, and no explicit patch text beyond Oracle’s CPU reference. Avoid expanding scope beyond Oracle Database Enterprise Edition Recovery.

Mitigation direction

  • Review Oracle’s July 2022 Critical Patch Update guidance for this CVE.
  • Confirm Oracle Database Enterprise Edition instances run supported versions.
  • Check vendor guidance before assuming a patch or workaround applies.
  • Restrict EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT to approved administrative accounts only.
  • Limit Oracle Net exposure to trusted administrative networks.

Validation and detection

  • Inventory Oracle Database Enterprise Edition deployments and support status.
  • Verify whether any database uses unsupported or legacy Oracle versions.
  • Audit who has EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT privilege.
  • Confirm Oracle Net is not broadly reachable from untrusted networks.
  • Review Oracle CPU documentation for any environment-specific notes.
Prepared
Confidence
medium
Sources
3

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

description · low confidence lookup

Database behavior lookup

The CVE wording references database injection or access, so collection and exfiltration review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.

Open ATT&CK lookup
cve · low confidence lookup

CVE-2022-21511 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
High
CVSS
7.2 (3.1)
Known Exploited
No
Published

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

1CVSS vectors
0Timeline events
0ADP providers
2Source links

CVSS vector scores

1 official score

We collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.

ScoreVersionSeverityVectorExploitImpactSource
7.2CVSS 3.1HighCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H1.25.9Primary CVE score

Vulnerability scoring details

Base CVSS 3.1 score

7.2High
CVSS 3.1 vector shape for CVE-2022-21511Attack VectorAttack ComplexityPrivileges RequiredUser InteractionScopeConfidentiality ImpactIntegrity ImpactAvailability Impact

Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NetworkAdjacentLocalPhysical
Attack Complexity
LowHigh
Privileges Required
NoneLowHigh
User Interaction
NoneRequired
Scope
ChangedUnchanged
Confidentiality Impact
HighLowNone
Integrity Impact
HighLowNone
Availability Impact
HighLowNone

Source materials

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Oracle CorporationDatabase - Enterprise EditionNoneListed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.