First published: Wed Jan 20 2021(Updated: )
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Text. CVSS 3.1 Base Score 3.1 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Text | =12.1.0.2 | |
Oracle Text | =12.2.0.1 | |
Oracle Text | =18c | |
Oracle Text | =19c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2021-2045 is low.
The affected versions are 12.1.0.2, 12.2.0.1, 18c, and 19c.
The vulnerability in Oracle Text component of Oracle Database Server allows a low privileged attacker with Create Session privilege and network access via Oracle Net to compromise Oracle Text.
The CVE-2021-2045 vulnerability is difficult to exploit.
You can find more information about CVE-2021-2045 at the following link: [CVE-2021-2045 Oracle Security Advisory](https://www.oracle.com/security-alerts/cpujan2021.html)