First published: Wed Oct 17 2018(Updated: )
Vulnerability in the Oracle GoldenGate component of Oracle GoldenGate (subcomponent: Manager). Supported versions that are affected are 12.1.2.1.0, 12.2.0.2.0 and 12.3.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via TCP to compromise Oracle GoldenGate. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle GoldenGate. CVSS 3.0 Base Score 7.5 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle GoldenGate | =12.1.2.1.0 | |
Oracle GoldenGate | =12.2.0.2.0 | |
Oracle GoldenGate | =12.3.0.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Oracle GoldenGate vulnerability is CVE-2018-2914.
The severity of CVE-2018-2914 is high, with a severity value of 7.5.
Versions 12.1.2.1.0, 12.2.0.2.0, and 12.3.0.1.0 of Oracle GoldenGate are affected by CVE-2018-2914.
An attacker can exploit CVE-2018-2914 by using a TCP network access to compromise Oracle GoldenGate.
You can find more information about CVE-2018-2914 on the Oracle website, SecurityFocus, and Tenable Security.