PT-2022-2428 · Oracle · Oracle Database - Enterprise Edition Sharding+1

Alexander Kornbrust

+1

·

Published

2022-04-19

·

Updated

2022-04-27

·

CVE-2022-21410

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Oracle Database - Enterprise Edition Sharding version 19c
Description The issue is related to insufficient input validation in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. This easily exploitable vulnerability allows a high-privileged attacker with Create Any Procedure privilege and network access via Oracle Net to compromise Oracle Database - Enterprise Edition Sharding, potentially resulting in a takeover.
Recommendations For Oracle Database - Enterprise Edition Sharding version 19c, update to a version that includes the fix for this issue. As a temporary workaround, consider restricting network access via Oracle Net to minimize the risk of exploitation. Restrict the Create Any Procedure privilege to only those users who require it, to reduce the potential attack surface.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02822
CVE-2022-21410

Affected Products

Oracle Database
Oracle Database - Enterprise Edition Sharding