CVE-2021-38475

The database connection to the server is performed by calling a specific API, which could allow an unprivileged user to gain SYSDBA permissions.

Credits

Amir Preminger of Claroty reported these vulnerabilities to CISA.

References