cbcvebase.

Oracle Database vulnerabilities

64 known vulnerabilities affecting oracle/database.

Total CVEs
64
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH16MEDIUM24LOW11

Vulnerabilities

Page 1 of 4
CVE-2016-2183P2HIGHCVSS 7.5PoCv11.2.0.4v12.1.0.22016-09-01
CVE-2016-2183 [HIGH] CWE-200 CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DE
nvd
CVE-2020-9484P2HIGHCVSS 7.0PoCv12.2.0.1v19c+1 more2020-05-20
CVE-2020-9484 [HIGH] CWE-502 CVE-2020-9484: When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7. When using Apache Tomcat versions 10.0.0-M1 to 10.0.0-M4, 9.0.0.M1 to 9.0.34, 8.5.0 to 8.5.54 and 7.0.0 to 7.0.103 if a) an attacker is able to control the contents and name of a file on the server; and b) the server is configured to use the PersistenceManager with a FileStore; and c) the PersistenceManager is configured with sessionAttributeValueClassN
nvd
CVE-2014-3566P3LOWCVSS 3.4PoCv11.2.0.4v12.1.0.22014-10-15
CVE-2014-3566 [LOW] CWE-310 CVE-2014-3566: The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CB The SSL protocol 3.0, as used in OpenSSL through 1.0.1i and other products, uses nondeterministic CBC padding, which makes it easier for man-in-the-middle attackers to obtain cleartext data via a padding-oracle attack, aka the "POODLE" issue.
nvd
CVE-2017-10202P3CRITICALCVSS 9.9v11.2.0.4v12.1.0.2+1 more2017-08-08
CVE-2017-10202 [CRITICAL] CVE-2017-10202: Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks
nvd
CVE-2021-25122P3HIGHCVSS 7.5v12.2.0.1v19c+1 more2021-03-01
CVE-2021-25122 [HIGH] CWE-200 CVE-2021-25122: When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 When responding to new h2c connection requests, Apache Tomcat versions 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41 and 8.5.0 to 8.5.61 could duplicate request headers and a limited amount of request body from one request to another meaning user A and user B could both see the results of user A's request.
nvd
CVE-2016-3454P3CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2016-04-21
CVE-2016-3454 [CRITICAL] CVE-2016-3454: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-3609P3CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2016-07-21
CVE-2016-3609 [CRITICAL] CVE-2016-3609: Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12 Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2020-29508P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-29508 [CRITICAL] CWE-331 CVE-2020-29508: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Improper Input Validation Vulnerability.
nvd
CVE-2020-29507P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-29507 [CRITICAL] CWE-20 CVE-2020-29507: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.4, and Dell BSAFE Micro Edition Suite, versions before 4.4, contain an Improper Input Validation Vulnerability.
nvd
CVE-2020-35169P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-35169 [CRITICAL] CWE-347 CVE-2020-35169: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Improper Input Validation Vulnerability.
nvd
CVE-2017-3310P3CRITICALCVSS 9.0v11.2.0.4v12.1.0.22017-01-27
CVE-2017-3310 [CRITICAL] CVE-2017-3310: Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. Successful attacks require human interaction from a pers
nvd
CVE-2020-29506P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-29506 [CRITICAL] CWE-385 CVE-2020-29506: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.5.2, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2020-35167P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-35167 [CRITICAL] CWE-200 CVE-2020-35167: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2020-35163P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-35163 [CRITICAL] CWE-330 CVE-2020-35163: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain a Use of Insufficiently Random Values Vulnerability.
nvd
CVE-2020-35166P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-35166 [CRITICAL] CWE-385 CVE-2020-35166: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2020-35168P3CRITICALCVSS 9.8v12.1.0.2v19c+1 more2022-07-11
CVE-2020-35168 [CRITICAL] CWE-311 CVE-2020-35168: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2017-10321P3HIGHCVSS 8.8v11.2.0.4v12.1.0.2+1 more2017-10-19
CVE-2017-10321 [HIGH] CVE-2017-10321: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. While the vulnerability is in Core RD
nvd
CVE-2020-5360P3HIGHCVSS 7.5v12.1.0.2v12.2.0.1+2 more2020-12-16
CVE-2020-5360 [HIGH] CWE-127 CVE-2020-5360: Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnera Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to a Buffer Under-Read Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability resulting in undefined behaviour, or a crash of the affected systems.
nvd
CVE-2019-2406P3HIGHCVSS 7.2v12.1.0.2v12.2.0.1+1 more2019-01-16
CVE-2019-2406 [HIGH] CVE-2019-2406: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can
nvd
CVE-2021-2337P3HIGHCVSS 7.2v12.1.0.2v12.2.0.1+1 more2021-07-21
CVE-2021-2337 [HIGH] CVE-2021-2337: Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are Vulnerability in the Oracle XML DB component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Public Synonym privilege with network access via Oracle Net to compromise Oracle XML DB. Successful attacks of this vulner
nvd
Oracle Database vulnerabilities | cvebase