Local Privilege Escalation in Oracle Database - Enterprise Edition Sharding
CVE-2022-21510

8.8HIGH

Key Information:

Vendor
Oracle
Vendor
CVE Published:
19 July 2022

Summary

A vulnerability exists in the Sharding component of Oracle Database - Enterprise Edition, which could be exploited by an attacker with low privileges who has local login access to the infrastructure where the database is executed. This flaw allows exploitation, potentially leading to the compromise of Sharding functionality. While the direct impact is on Oracle Database - Enterprise Edition Sharding, successful attacks may have broader implications for other interconnected Oracle systems.

Affected Version(s)

Database - Enterprise Edition None

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.