PT-2021-1766 · Oracle · Oracle Database Server+1

Eddie Zhu

·

Published

2021-01-19

·

Updated

2021-01-26

·

CVE-2021-2054

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Oracle Database Server versions 12.2.0.1, 18c, 19c
Description: The issue is related to the RDBMS Sharding component of Oracle Database Server, where an easily exploitable vulnerability allows a high-privileged attacker with network access via Oracle Net to compromise RDBMS Sharding. This can result in the takeover of RDBMS Sharding. The vulnerability is associated with inadequate access control and can be exploited by an attacker with Create Any Procedure, Create Any View, Create Any Trigger privilege.
Recommendations: For versions 12.2.0.1, 18c, and 19c, consider restricting access to the RDBMS Sharding component until a patch is available. As a temporary workaround, limit the privileges of users with Create Any Procedure, Create Any View, Create Any Trigger privilege to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-00467
CVE-2021-2054
ZDI-21-083

Affected Products

Oracle Database
Oracle Database Server