PT-2018-1404 · Oracle · Oracle Database

Published

2018-07-17

·

Updated

2019-10-03

·

CVE-2018-2939

CVSS v3.1

8.4

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1, and 18.2
Description The issue is related to insufficient access control in the Core RDBMS component of Oracle Database Server. It can be easily exploited by a low-privileged attacker with local logon privileges, potentially compromising the Core RDBMS and impacting additional products. Successful attacks may result in unauthorized access to critical data, including creation, deletion, or modification, as well as the ability to cause a hang or crash of the Core RDBMS.
Recommendations For versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1, and 18.2, consider restricting local logon privileges to minimize the risk of exploitation until a patch is available. As a temporary workaround, limit access to the Core RDBMS component to reduce the potential impact of the issue. Avoid using the Core RDBMS component for critical data storage or processing until the issue is resolved.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2018-00953
CVE-2018-2939

Affected Products

Oracle Database