Vulnerability in Core RDBMS of Oracle Database Server
CVE-2020-2510

7.5HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

A vulnerability exists in the Core RDBMS component of the Oracle Database Server, enabling an unauthenticated attacker with network access via OracleNet to potentially exploit the system. The exploitation requires human interaction from a third party, complicating the attack vector. Successful exploitation of this flaw can lead to a complete takeover of the Core RDBMS, significantly impacting the confidentiality, integrity, and availability of the database. Immediate patching and monitoring of the affected Oracle Database versions are crucial to safeguard organizational data.

Affected Version(s)

Oracle Database 11.2.0.4

Oracle Database 12.1.0.2

Oracle Database 12.2.0.1

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.