Vulnerability in Oracle GoldenGate Monitoring Manager Affects Multiple Versions
CVE-2018-2913

10CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

This security vulnerability in the Monitoring Manager of Oracle GoldenGate allows an unauthenticated attacker with network access via TCP to gain control over the Oracle GoldenGate environment. Affected versions include 12.1.2.1.0, 12.2.0.2.0, and 12.3.0.1.0. Successful exploitation can lead to significant impacts on confidentiality, integrity, and availability, potentially compromising not only Oracle GoldenGate but also auxiliary products associated with it.

Affected Version(s)

GoldenGate 12.1.2.1.0

GoldenGate 12.2.0.2.0

GoldenGate 12.3.0.1.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.