Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 7.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
References
Link | Resource |
---|---|
https://www.oracle.com/security-alerts/cpujan2020.html | Patch Vendor Advisory |
https://www.oracle.com/security-alerts/cpujan2020.html | Patch Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:25
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.oracle.com/security-alerts/cpujan2020.html - Patch, Vendor Advisory |
Information
Published : 2020-01-15 17:15
Updated : 2024-11-21 05:25
NVD link : CVE-2020-2518
Mitre link : CVE-2020-2518
CVE.ORG link : CVE-2020-2518
JSON object : View
Products Affected
oracle
- database_server
CWE