CVE-2021-2054: Oracle Database Procedure Improper Privilege Management Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Oracle Database. Authentication is required to exploit this vulnerability. The specific flaw exists within the execution of stored procedures. When executing stored procedures, the process does not properly check the caller's privileges. An attacker can leverage this vulnerability to escalate privileges to resources normally protected from users with limited privileges.
Other sources
Vulnerability in the RDBMS Sharding component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Any View, Create Any Trigger privilege with network access via Oracle Net to compromise RDBMS Sharding. Successful attacks of this vulnerability can result in takeover of RDBMS Sharding. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-2054?
CVE-2021-2054 is a vulnerability in the RDBMS Sharding component of Oracle Database Server, affecting versions 12.2.0.1, 18c, and 19c.
What is the severity of CVE-2021-2054?
CVE-2021-2054 has a severity rating of 8.8 (High).
How does CVE-2021-2054 impact Oracle Database Server?
CVE-2021-2054 allows a high privileged attacker with specific privileges to escalate privileges and gain unauthorized access to the Oracle Database Server.
Which versions of Oracle Database Server are affected by CVE-2021-2054?
Oracle Database Server versions 12.2.0.1, 18c, and 19c are affected by CVE-2021-2054.
How can I fix CVE-2021-2054 in Oracle Database Server?
To fix CVE-2021-2054 in Oracle Database Server, apply the patches and updates provided by Oracle in their security advisory.