First published: Tue Apr 23 2019(Updated: )
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Clusterware. While the vulnerability is in Portable Clusterware, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Portable Clusterware. CVSS 3.0 Base Score 8.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H).
Credit: secalert_us@oracle.com secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database | =11.2.0.4 | |
Oracle Database | =12.1.0.2 | |
Oracle Database | =12.2.0.1 | |
Oracle Database | =18c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2516 is considered a high severity vulnerability due to its exploitable nature by high privileged attackers.
To fix CVE-2019-2516, apply the latest Oracle patches as recommended in Oracle's security advisories.
CVE-2019-2516 affects Oracle Database versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18c.
Yes, CVE-2019-2516 can be exploited remotely by attackers who have the appropriate privileges.
CVE-2019-2516 impacts the Portable Clusterware component of Oracle Database Server.