Vulnerability in Core RDBMS of Oracle Database Server
CVE-2019-2956

5.7MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
16 October 2019

Summary

A vulnerability exists in the Core RDBMS component of Oracle Database Server, specifically within jackson-databind. This flaw affects versions 12.1.0.2, 12.2.0.1, 18c, and 19c. It can be exploited by an attacker with low privileges who possesses the Create Session privilege and has network access through various protocols. Successful exploitation can lead to unauthorized manipulation that may result in the database process hanging or repeatedly crashing, leading to a denial-of-service condition. Attacks require interaction from a user other than the attacker, thus posing a unique risk.

Affected Version(s)

Oracle Database 12.1.0.2

Oracle Database 12.2.0.1

Oracle Database 18c

References

CVSS V3.1

Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.