CVE-2021-1993: Medium severity oracle database vulnerability
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Java VM accessible data. CVSS 3.1 Base Score 4.8 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-1993?
The severity of CVE-2021-1993 is medium.
Which versions of Oracle Database Server are affected by CVE-2021-1993?
Oracle Database Server versions 12.1.0.2, 12.2.0.1, 18c, and 19c are affected by CVE-2021-1993.
What privilege does an attacker need to exploit CVE-2021-1993?
An attacker needs the Create Session privilege with network access via Oracle Net to exploit CVE-2021-1993.
How can CVE-2021-1993 be exploited?
CVE-2021-1993 can be exploited through the Java VM component of Oracle Database Server.
Where can I find more information about CVE-2021-1993?
More information about CVE-2021-1993 can be found at: https://www.oracle.com/security-alerts/cpujan2021.html