Database Gateway for ODBC Vulnerability in Oracle Database Server
CVE-2020-2515

5MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
15 January 2020

Summary

A vulnerability exists in the Database Gateway for ODBC component of Oracle Database Server, impacting versions 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c, and 19c. This vulnerability could be exploited by low privileged attackers who possess Create Session privileges, allowing them to manipulate accessible data through unauthorized updates, inserts, or deletions. Additionally, they may gain unauthorized read access to specific data and potentially initiate a partial denial of service on the Database Gateway for ODBC. This presents a significant risk for data integrity and confidentiality.

Affected Version(s)

Oracle Database 11.2.0.4

Oracle Database 12.1.0.2

Oracle Database 12.2.0.1

References

CVSS V3.1

Score:
5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.