CVE-2017-10261: Infoleak
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where XML Database executes to compromise XML Database. While the vulnerability is in XML Database, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all XML Database accessible data. Note: This score is for Windows platform version 11.2.0.4 of Database. For Windows platform version 12.1.0.2 and Linux, the score is 5.5 with scope Unchanged. CVSS 3.0 Base Score 6.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2017-10261?
CVE-2017-10261 is rated as a medium severity vulnerability.
How do I fix CVE-2017-10261?
To fix CVE-2017-10261, apply the appropriate security patches released by Oracle for affected versions.
Which versions of Oracle Database are affected by CVE-2017-10261?
CVE-2017-10261 affects Oracle Database versions 11.2.0.4 and 12.1.0.2.
What type of access is required to exploit CVE-2017-10261?
Exploitation of CVE-2017-10261 requires low privileged access with Create Session privilege.
What component is affected by CVE-2017-10261?
CVE-2017-10261 affects the XML Database component of Oracle Database Server.