I have tried to set “DYNAMIC_REGISTRATION_LISTENER = OFF” and “SECURE_REGISTER_LISTENER = (IPC)” work-around, but this will make remote access to the database fails. If I set “VALID_NODE_CHECKING_REGISTRATION = LOCAL”, the vulnerability issue is still there.