First published: Wed Oct 17 2018(Updated: )
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =11.2.0.4 | |
Oracle Database | =12.1.0.2 | |
Oracle Database | =12.2.0.1 | |
Oracle Database | =18c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-3259 is classified as easily exploitable, allowing unauthenticated attackers to compromise the Java VM in affected Oracle Database versions.
To fix CVE-2018-3259, apply the latest security patch provided by Oracle for your affected database version.
CVE-2018-3259 affects Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18c.
CVE-2018-3259 can be exploited by unauthenticated attackers with network access, making it highly concerning.
CVE-2018-3259 specifically affects the Java VM component within Oracle Database Server.