PT-2018-1404 · Oracle · Oracle Database

Publicado

2018-07-17

·

Atualizado

2019-10-03

·

CVE-2018-2939

CVSS v3.1

8.4

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1, and 18.2
Description The issue is related to insufficient access control in the Core RDBMS component of Oracle Database Server. It can be easily exploited by a low-privileged attacker with local logon privileges, potentially compromising the Core RDBMS and impacting additional products. Successful attacks may result in unauthorized access to critical data, including creation, deletion, or modification, as well as the ability to cause a hang or crash of the Core RDBMS.
Recommendations For versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1, and 18.2, consider restricting local logon privileges to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit access to the Core RDBMS component to reduce the potential impact of the issue. Avoid using the Core RDBMS component for critical data storage or processing until the issue is resolved.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2018-00953
CVE-2018-2939

Produtos afetados

Oracle Database