- Description
- Vulnerability in the PL/SQL component of Oracle Database Server. Supported versions that are affected are 19.3-19.20 and 21.3-21.11. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute on sys.utl_http privilege with network access via Oracle Net to compromise PL/SQL. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in PL/SQL, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of PL/SQL accessible data as well as unauthorized read access to a subset of PL/SQL accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of PL/SQL. CVSS 3.1 Base Score 5.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L).
- Source
- secalert_us@oracle.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 5.9
- Impact score
- 3.7
- Exploitability score
- 1.7
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:L
- Severity
- MEDIUM
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:oracle:database_server:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "32E02E1D-EF08-47A1-9095-06F9F2D8D268",
"versionEndIncluding": "19.20",
"versionStartIncluding": "19.3"
},
{
"criteria": "cpe:2.3:a:oracle:database_server:*:*:*:*:enterprise:*:*:*",
"vulnerable": true,
"matchCriteriaId": "84088F94-42E8-4553-AE33-A5C4E954C83F",
"versionEndIncluding": "21.11",
"versionStartIncluding": "21.3"
}
],
"operator": "OR"
}
]
}
]