PT-2019-2778 · Oracle · Oracle Odbc Driver+2

Published

2019-01-01

·

Updated

2020-08-24

·

CVE-2019-2799

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Database Server versions 11.2.0.4 through 18c
Description The issue is related to the Oracle ODBC Driver component, which has a vulnerability that can be exploited by a low-privileged attacker with network access via multiple protocols. This can result in the takeover of the Oracle ODBC Driver. The vulnerability affects Windows platforms only.
Recommendations For versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18c, consider disabling the Oracle ODBC Driver component until a patch is available to prevent potential exploitation. As a temporary workaround, restrict access to the Oracle ODBC Driver to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-02725
CVE-2019-2799
ZDI-19-662

Affected Products

Oracle Database
Oracle Database Server
Oracle Odbc Driver