First published: Thu Oct 19 2017(Updated: )
An unspecified vulnerability in Oracle Database Server related to the RDBMS Security component could allow an authenticated attacker to cause no confidentiality impact, low integrity impact, and no availability impact.
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =11.2.0.4 | |
Oracle Database | =12.1.0.2 | |
Oracle Database | =12.2.0.1 | |
IBM ISIM VA | <=7.0.2 | |
IBM ISIM VA | <=7.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2017-10292 is low with a severity value of 2.3.
The affected software for CVE-2017-10292 is Oracle Database Server versions 11.2.0.4, 12.1.0.2, and 12.2.0.1, as well as IBM ISIM VA versions 7.0.2 and 7.0.1.
Yes, CVE-2017-10292 is easily exploitable.
An attacker with high privileges having Create User privilege with logon to the infrastructure where RDBMS Security executes can exploit CVE-2017-10292.
Yes, Oracle has provided a security advisory with information on how to address CVE-2017-10292. Please refer to the Oracle website for more details.