PT-2021-7121 · Oracle · Oracle Database Server+1
Yaoguang Chen
·
Published
2021-07-20
·
Updated
2021-07-21
·
CVE-2021-2330
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server version 19c
Description
The issue is related to insufficient input validation in the Core RDBMS component of Oracle Database Server. This allows a low-privileged attacker with Create Table privilege and network access via Oracle Net to compromise Core RDBMS, potentially resulting in a partial denial of service.
Recommendations
For version 19c, apply the necessary patches or updates to resolve the issue. As a temporary workaround, consider restricting network access via Oracle Net to minimize the risk of exploitation. Additionally, limit the Create Table privilege to authorized users only.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Database
Oracle Database Server