PT-2016-1087 · Oracle · Oracle Database Server

Published

2016-01-19

·

Updated

2016-12-07

·

CVE-2016-0472

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:P
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 11.2.0.4, 12.1.0.1, and 12.1.0.2
Description The issue is related to an unspecified vulnerability in the XDB - XML Database component, allowing remote authenticated users to affect confidentiality and availability. Exploitation of this vulnerability may enable a remote attacker to read data or cause a partial denial of service using network packets.
Recommendations For Oracle Database Server version 11.2.0.4, update to a version that includes the fix for this issue. For Oracle Database Server version 12.1.0.1, update to a version that includes the fix for this issue. For Oracle Database Server version 12.1.0.2, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting access to the XDB - XML Database component to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-00157
CVE-2016-0472

Affected Products

Oracle Database Server