CVE-2014-2406: High severity Oracle Database Server vulnerability
Unspecified vulnerability in the Core RDBMS component in Oracle Database Server 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to "Advisor" and "Select Any Dictionary" privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2406?
CVE-2014-2406 has a severity rating that can impact confidentiality, integrity, and availability for affected Oracle Database versions.
How do I fix CVE-2014-2406?
To mitigate CVE-2014-2406, users should apply the latest security patches provided by Oracle for the affected database versions.
Which Oracle Database versions are affected by CVE-2014-2406?
CVE-2014-2406 affects Oracle Database Server versions 11.1.0.7, 11.2.0.3, 11.2.0.4, and 12.1.0.1.
Who can exploit CVE-2014-2406?
CVE-2014-2406 can be exploited by remote authenticated users with specific privileges related to "Advisor" and "Select Any Dictionary."
What impact does CVE-2014-2406 have on my Oracle Database?
The impact of CVE-2014-2406 can potentially affect the confidentiality, integrity, and availability of the database depending on the exploitation.