First published: Wed Oct 21 2020(Updated: )
Vulnerability in the SQL Developer Install component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Client Computer User Account privilege with logon to the infrastructure where SQL Developer Install executes to compromise SQL Developer Install. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of SQL Developer Install accessible data. CVSS 3.1 Base Score 2.8 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle SQL Developer | =11.2.0.4 | |
Oracle SQL Developer | =12.1.0.2 | |
Oracle SQL Developer | =12.2.0.1 | |
Oracle SQL Developer | =18c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2020-14740.
The title of the vulnerability is 'Vulnerability in the SQL Developer Install component of Oracle Database Server.'
The affected versions of Oracle Database Server are 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18c.
The severity of CVE-2020-14740 is low with a severity value of 2.8.
To fix CVE-2020-14740, you should update your Oracle Database Server to a patched version provided by Oracle.