Vulnerability in Core RDBMS of Oracle Database Server
CVE-2019-2956
5.7MEDIUM
Summary
A vulnerability exists in the Core RDBMS component of Oracle Database Server, specifically within jackson-databind. This flaw affects versions 12.1.0.2, 12.2.0.1, 18c, and 19c. It can be exploited by an attacker with low privileges who possesses the Create Session privilege and has network access through various protocols. Successful exploitation can lead to unauthorized manipulation that may result in the database process hanging or repeatedly crashing, leading to a denial-of-service condition. Attacks require interaction from a user other than the attacker, thus posing a unique risk.
Affected Version(s)
Oracle Database 12.1.0.2
Oracle Database 12.2.0.1
Oracle Database 18c
References
CVSS V3.1
Score:
5.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved