PT-2016-1083 · Oracle · Oracle Database Server

Published

2016-01-19

·

Updated

2016-12-07

·

CVE-2016-0461

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 11.2.0.4, 12.1.0.1, and 12.1.0.2
Description The issue is related to errors in the code of the XDB - XML Database component, allowing remote authenticated users to affect availability. Exploitation of this issue may enable a remote attacker to cause a partial denial of service using network packets.
Recommendations For Oracle Database Server version 11.2.0.4, update to a version that includes the fix for this issue. For Oracle Database Server version 12.1.0.1, update to a version that includes the fix for this issue. For Oracle Database Server version 12.1.0.2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the XDB - XML Database component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00153
CVE-2016-0461

Affected Products

Oracle Database Server