CVE-2018-3259: Critical severity oracle database vulnerability
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2018-3259?
CVE-2018-3259 is classified as easily exploitable, allowing unauthenticated attackers to compromise the Java VM in affected Oracle Database versions.
How do I fix CVE-2018-3259?
To fix CVE-2018-3259, apply the latest security patch provided by Oracle for your affected database version.
Which versions of Oracle Database are affected by CVE-2018-3259?
CVE-2018-3259 affects Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18c.
What kind of access is required to exploit CVE-2018-3259?
CVE-2018-3259 can be exploited by unauthenticated attackers with network access, making it highly concerning.
What components are affected by CVE-2018-3259?
CVE-2018-3259 specifically affects the Java VM component within Oracle Database Server.