CVE-2011-2244Improper Input Validation in Oracle Database Server

Severity
6.4MEDIUMNVD
EPSS
0.3%
top 48.92%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 20
Latest updateMay 17

Description

Unspecified vulnerability in the Security Framework component in Oracle Database Server 10.1.0.5, 10.2.0.3, 10.2.0.4, 10.2.0.5, 11.1.0.7, 11.2.0.1, and 11.2.0.2; and Enterprise Manager Grid Control 10.1.0.6, 10.2.0.5, and 11.1.0.1; allows remote attackers to affect confidentiality and integrity via unknown vectors related to Authentication.

CVSS vector

AV:N/AC:L/C:P/I:P/A:NExploitability: 10.0 | Impact: 4.9

Affected Packages2 packages

NVDoracle/enterprise_manager_grid_control10.1.0.6, 10.2.0.5, 11.1.0.1+2
NVDoracle/database_server7 versions+6

Patches

🔴Vulnerability Details

2
GHSA
GHSA-qgwg-3632-v4h2: Unspecified vulnerability in the Security Framework component in Oracle Database Server 102022-05-17
CVEList
CVE-2011-2244: Unspecified vulnerability in the Security Framework component in Oracle Database Server 102011-07-20

📋Vendor Advisories

2
Red Hat
avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)2011-01-04
Red Hat
avahi: daemon infinite loop triggered by an empty UDP packet (CVE-2010-2244 fix regression)2011-01-04

💬Community

1
Bugzilla
CVE-2011-1002 avahi: avahi daemon remote DoS by sending NULL UDP (due incorrect CVE-2010-2244 fix) [fedora-all]2011-02-23
CVE-2011-2244 — Improper Input Validation in Oracle | cvebase