First published: Fri Aug 10 2018(Updated: )
A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =11.2.0.4 | |
Oracle Database | =12.1.0.2 | |
Oracle Database | =12.2.0.1 | |
Oracle Database | =18 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3110 is considered an easily exploitable vulnerability with critical severity.
To fix CVE-2018-3110, apply the latest patches or updates provided by Oracle for the affected database versions.
CVE-2018-3110 affects Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18.
Exploitation of CVE-2018-3110 requires low privileged attacker access with the Create Session privilege.
Yes, network access via Oracle Net is necessary for an attacker to exploit CVE-2018-3110.