Unspecified Vulnerability in Oracle Database Server Programmable Interface
CVE-2016-5505

5.5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
25 October 2016

Summary

An unspecified vulnerability exists within the RDBMS Programmable Interface of Oracle Database Server versions 11.2.0.4 and 12.1.0.2, allowing local users to potentially compromise the confidentiality of sensitive data through unknown vectors. This vulnerability poses a risk as it can be exploited by users with local access to the database system, highlighting the importance of access control and regular security assessments.

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.