First published: Wed Oct 16 2019(Updated: )
Vulnerability in the Core RDBMS (jackson-databind) component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise Core RDBMS (jackson-databind). Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Core RDBMS (jackson-databind). CVSS 3.0 Base Score 5.7 (Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database Server | =12.1.0.2 | |
Oracle Database Server | =12.2.0.1 | |
Oracle Database Server | =18c | |
Oracle Database Server | =19c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-2956 is a vulnerability in the Core RDBMS (jackson-databind) component of Oracle Database Server.
Oracle Database Server versions 12.1.0.2, 12.2.0.1, 18c, and 19c are affected by CVE-2019-2956.
The severity of CVE-2019-2956 is medium with a CVSS score of 5.7.
CVE-2019-2956 can be easily exploited by a low privileged attacker with Create Session privilege and network access via multiple protocols.
You can find more information about CVE-2019-2956 in the Oracle security advisory: http://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html