Vulnerability in Oracle Text Component of Oracle Database Server
CVE-2018-3299
8.2HIGH
Summary
The vulnerability in the Oracle Text component of Oracle Database Server allows an unauthenticated attacker with network access to exploit the system via multiple protocols. Successful exploitation, requiring human interaction, leads to severe consequences including unauthorized data manipulation and potential Denial of Service attacks, resulting in application instability, such as crashes or hangs. This issue may also impact other Oracle products linked to Oracle Text, necessitating immediate attention by system administrators to protect data integrity and system availability.
Affected Version(s)
Text 11.2.0.4
Text 12.1.0.2
Text 12.2.0.1
References
CVSS V3.1
Score:
8.2
Severity:
HIGH
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved