PT-2022-3787 · Oracle · Oracle Database
Emad Al-Mousa
·
Published
2022-07-19
·
Updated
2022-07-23
·
CVE-2022-21432
CVSS v2.0
4.0
Medium
| Vector | AV:N/AC:L/Au:S/C:N/I:N/A:P |
Name of the Vulnerable Software and Affected Versions
Oracle Database - Enterprise Edition RDBMS Security versions 12.1.0.2, 19c, and 21c
Description
The issue is related to errors in resource release in the Oracle Database - Enterprise Edition RDBMS Security component of Oracle Database Server. Exploitation of this issue can allow a remote attacker to cause a denial of service using the Oracle Net protocol. A highly privileged attacker with DBA role privilege and network access via Oracle Net can compromise Oracle Database - Enterprise Edition RDBMS Security, resulting in the ability to cause a partial denial of service.
Recommendations
For version 12.1.0.2, update to a version that includes the fix for this issue.
For version 19c, update to a version that includes the fix for this issue.
For version 21c, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to the Oracle Net protocol to minimize the risk of exploitation.
Fix
Improper Resource Release
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Database