Identity and access security
CVE-2023-23951: Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the app…
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
Published
ExploitedNot in CISA KEV
Ransomware useNot reportedPer CISA
SeverityMEDIUMCVSS 3.1 6.1
EPSS0.51%Chance of exploitation in 30 days
Public exploitNot tracked
FixNot yet
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Symantec Identity Management And Governance 14.3, 14 | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
Ability to enumerate the Oracle LDAP attributes for the current user by modifying the query used by the application
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.