Description
Vulnerability in the RDBMS Scheduler component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Export Full Database privilege with network access via Oracle Net to compromise RDBMS Scheduler. Successful attacks of this vulnerability can result in takeover of RDBMS Scheduler. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Affected products
- Oracle Corporation / Database - Enterprise Edition12.1.0.2 – 12.1.0.2
- Oracle Corporation / Database - Enterprise Edition12.2.0.1 – 12.2.0.1
- Oracle Corporation / Database - Enterprise Edition18c – 18c
- Oracle Corporation / Database - Enterprise Edition19c – 19c
References
- VENDOR_ADVISORYhttps://www.oracle.com/security-alerts/cpujan2021.html