CVE-2019-2734: Medium severity oracle database vulnerability
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Execute on DBMSADVISOR privilege with network access via OracleNet to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Core RDBMS accessible data. CVSS 3.0 Base Score 4.3 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-2734?
The severity of CVE-2019-2734 is medium with a severity value of 4.3.
Which versions of Oracle Database Server are affected by CVE-2019-2734?
Oracle Database Server versions 12.2.0.1, 18c, and 19c are affected by CVE-2019-2734.
What privileges does an attacker need to exploit CVE-2019-2734?
An attacker needs the Create Session and Execute on DBMS_ADVISOR privileges with network access via OracleNet to exploit CVE-2019-2734.
How can I fix CVE-2019-2734?
To fix CVE-2019-2734, apply the necessary patches provided by Oracle as mentioned in their security advisory.