First published: Wed Jan 19 2022(Updated: )
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Core RDBMS accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database Server | =12.2.0.1 | |
Oracle Database Server | =19c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21247.
The severity level of CVE-2022-21247 is medium.
The affected versions of Oracle Database Server are 12.2.0.1 and 19c.
An attacker needs to have Create Session and Execute Catalog Role privileges with network access via Oracle Net.
You can find more information about CVE-2022-21247 at the following link: https://www.oracle.com/security-alerts/cpujan2022.html