CVE-2020-2516: Low severity Oracle Database Server vulnerability
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Materialized View, Create Table privilege with network access via OracleNet to compromise Core RDBMS. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Core RDBMS accessible data. CVSS 3.0 Base Score 2.4 (Integrity impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Oracle Database Server vulnerability?
The vulnerability ID for this Oracle Database Server vulnerability is CVE-2020-2516.
Which versions of Oracle Database Server are affected by this vulnerability?
The vulnerability affects Oracle Database Server versions 12.1.0.2, 12.2.0.1, 18c, and 19c.
What privileges does an attacker need to exploit this vulnerability?
A high privileged attacker with Create Materialized View and Create Table privileges and network access via OracleNet can exploit this vulnerability.
How severe is this Oracle Database Server vulnerability?
This vulnerability has a severity rating of low with a CVSS score of 2.4.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following link: [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpujan2020.html)