Denial of Service Vulnerability in Oracle GoldenGate by Oracle
CVE-2018-2914

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
17 October 2018

Summary

A vulnerability exists in the Oracle GoldenGate component, specifically within the Manager subcomponent. This issue allows unauthenticated attackers with network access via TCP to exploit the system. If successfully exploited, it can lead to unauthorized actions that may cause the Oracle GoldenGate service to hang or crash repeatedly, resulting in a complete Denial of Service (DoS). The supported affected versions include 12.1.2.1.0, 12.2.0.2.0, and 12.3.0.1.0.

Affected Version(s)

GoldenGate 12.1.2.1.0

GoldenGate 12.2.0.2.0

GoldenGate 12.3.0.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.