CVE-2018-3110
published 2018-08-10CVE-2018-3110: A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and…
PriorityP358critical9.9CVSS 3.0
AVNACLPRLUINSCCHIHAH
EPSS
2.48%
82.7th percentile
A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle_corporation | oracle_database | — | — |
| oracle_corporation | oracle_database | — | — |
| oracle_corporation | oracle_database | — | — |
| oracle_corporation | oracle_database | — | — |
CVSS provenance
nvdv3.09.9CRITICALCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
Tenable
Oracle JavaVM Database Takeover
blogs_tenable·2018-08-15·CVSS 5.3
[MEDIUM] Oracle JavaVM Database Takeover
Blog / Cyber Exposure Alerts
Subscribe
# Oracle JavaVM Database Takeover
Paul Davis
August 15, 2018
2 Min Read
A new vulnerability discovered in the Oracle Database JavaVM component can result in complete database compromise and shell access to the underlying server.
## Background
Oracle released an out-of-band update to its flagship database product for an authenticated vulnerability in the JavaVM component. According to Oracle, the vulnerability "can result in complete compromise of the Oracle Database and shell access to the underlying server." The same issue was found and patched in the July 2018 critical patch update (CPU) but was not reported as a critical vulnerability for unspecified reasons.
## Vulnerability details
According to Oracle, this vulnerability affects “...vers
Tenable
Oracle JavaVM Database Takeover
blogs_tenable·2018-08-15
Oracle JavaVM Database Takeover
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.htmlhttp://www.securityfocus.com/bid/105056http://www.securitytracker.com/id/1041532http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.htmlhttp://www.securityfocus.com/bid/105056http://www.securitytracker.com/id/1041532
2018-08-10
Published