PT-2017-3893 · Oracle · Oracle Database Server+1

Published

2017-12-15

·

Updated

2019-10-17

·

CVE-2018-2875

CVSS v3.1

5.0

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 12.2.0.1, 18c, and 19c
Description The issue is related to a vulnerability in the Core RDBMS component of Oracle Database Server, which can be easily exploited by a low-privileged attacker with Create Session privilege and network access via OracleNet. This can lead to unauthorized read access to a subset of Core RDBMS accessible data. The vulnerability may also impact additional products.
Recommendations For version 12.2.0.1, update to a newer version to mitigate the risk. For version 18c, update to a newer version to mitigate the risk. For version 19c, update to a newer version to mitigate the risk. As a temporary workaround, consider restricting access to the Core RDBMS component until a patch is available. Restrict network access via OracleNet to minimize the risk of exploitation.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04207
CVE-2018-2875

Affected Products

Oracle Database
Oracle Database Server