CVE-2022-21511: High severity oracle database vulnerability
Vulnerability in the Oracle Database - Enterprise Edition Recovery component of Oracle Database Server. For supported versions that are affected see note. Easily exploitable vulnerability allows high privileged attacker having EXECUTE ON DBMSIR.EXECUTESQLSCRIPT privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Recovery. Successful attacks of this vulnerability can result in takeover of Oracle Database - Enterprise Edition Recovery. Note: None of the supported versions are affected. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-21511?
CVE-2022-21511 is a vulnerability in the Oracle Database - Enterprise Edition Recovery component of Oracle Database Server.
What versions of Oracle Database Enterprise Edition are affected by CVE-2022-21511?
For the supported versions of Oracle Database Enterprise Edition that are affected, please refer to the provided reference link: https://www.oracle.com/security-alerts/cpujul2022.html
How severe is CVE-2022-21511?
The severity of CVE-2022-21511 is rated as high with a severity score of 7.2.
How does CVE-2022-21511 affect Oracle Database?
CVE-2022-21511 allows a high privileged attacker with the EXECUTE ON DBMS_IR.EXECUTESQLSCRIPT privilege and network access to exploit the vulnerability.
How can I mitigate CVE-2022-21511?
To mitigate CVE-2022-21511, it is recommended to apply the necessary security patches provided by Oracle. Please refer to the provided reference link for more information: https://www.oracle.com/security-alerts/cpujul2022.html