First published: Wed Apr 16 2014(Updated: )
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to "Advisor" and "Select Any Dictionary" privileges.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =11.1.0.7 | |
Oracle Database | =11.2.0.3 | |
Oracle Database | =11.2.0.4 | |
Oracle Database | =12.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-2406 has a severity rating that can impact confidentiality, integrity, and availability for affected Oracle Database versions.
To mitigate CVE-2014-2406, users should apply the latest security patches provided by Oracle for the affected database versions.
CVE-2014-2406 affects Oracle Database Server versions 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1.
CVE-2014-2406 can be exploited by remote authenticated users with specific privileges related to "Advisor" and "Select Any Dictionary."
The impact of CVE-2014-2406 can potentially affect the confidentiality, integrity, and availability of the database depending on the exploitation.