Oracle Database Enterprise Edition RDBMS Security Vulnerability Affecting Multiple Versions
CVE-2022-21432

2.7LOW

Key Information:

Vendor
Oracle
Status
Vendor
CVE Published:
19 July 2022

Summary

A vulnerability exists within the Oracle Database - Enterprise Edition RDBMS Security component, which can be exploited by an attacker with DBA role privileges and network access. This flaw affects supported versions 12.1.0.2, 19c, and 21c, allowing unauthorized users to induce a partial denial of service (partial DOS) on the system. Successful exploitation can compromise the integrity of the RDBMS Security, putting databases at risk.

Affected Version(s)

Text 12.1.0.2

Text 19c

Text 21c

References

CVSS V3.1

Score:
2.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.