cbcvebase.

Oracle Database vulnerabilities

64 known vulnerabilities affecting oracle/database.

Total CVEs
64
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH16MEDIUM24LOW11

Vulnerabilities

Page 2 of 4
CVE-2016-3479P3HIGHCVSS 7.5v11.2.0.4v12.1.0.22016-07-21
CVE-2016-3479 [HIGH] CVE-2016-3479: Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 a Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2021-25329P3HIGHCVSS 7.0v12.2.0.1v19c+1 more2021-03-01
CVE-2021-25329 [HIGH] CVE-2021-25329: The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to The fix for CVE-2020-9484 was incomplete. When using Apache Tomcat 10.0.0-M1 to 10.0.0, 9.0.0.M1 to 9.0.41, 8.5.0 to 8.5.61 or 7.0.0. to 7.0.107 with a configuration edge case that was highly unlikely to be used, the Tomcat instance was still vulnerable to CVE-2020-9494. Note that both the previously published prerequisites for CVE-2020-9484 and the previously
nvd
CVE-2022-21596P3HIGHCVSS 7.2v19c2022-10-18
CVE-2022-21596 [HIGH] CVE-2022-21596: Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Database Server. The sup Vulnerability in the Oracle Database - Advanced Queuing component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having DBA user privilege with network access via Oracle Net to compromise Oracle Database - Advanced Queuing. Successful attacks of this vulnerability can
nvd
CVE-2020-35164P3HIGHCVSS 8.1v12.1.0.2v19c+1 more2022-07-11
CVE-2020-35164 [HIGH] CWE-385 CVE-2020-35164: Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versio Dell BSAFE Crypto-C Micro Edition, versions before 4.1.5, and Dell BSAFE Micro Edition Suite, versions before 4.6, contain an Observable Timing Discrepancy Vulnerability.
nvd
CVE-2022-21410P3HIGHCVSS 7.2v19c2022-04-19
CVE-2022-21410 [HIGH] CVE-2022-21410: Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Serv Vulnerability in the Oracle Database - Enterprise Edition Sharding component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Sharding. Successful
nvd
CVE-2023-21934P3MEDIUMCVSS 6.8v19cv21c2023-04-18
CVE-2023-21934 [MEDIUM] CVE-2023-21934: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affec Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having User Account privilege with network access via TLS to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creation, deletion or mod
nvd
CVE-2020-26185P3HIGHCVSS 7.5v12.1.0.2v19c+1 more2022-06-01
CVE-2020-26185 [HIGH] CWE-20 CVE-2020-26185: Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability. Dell BSAFE Micro Edition Suite, versions prior to 4.5.1, contain a Buffer Over-Read Vulnerability.
nvd
CVE-2022-21565P3MEDIUMCVSS 6.5v12.1.0.2v19c+1 more2022-07-19
CVE-2022-21565 [MEDIUM] CVE-2022-21565: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks of this vulnerability can result in unauthorized creat
nvd
CVE-2019-2619P3HIGHCVSS 8.2v11.2.0.4v12.1.0.2+2 more2019-04-23
CVE-2019-2619 [HIGH] CVE-2019-2619: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions th Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Cluste
nvd
CVE-2008-1814P3CRITICALCVSS 9.0v9.0.1.5v9.2.0.8+3 more2008-04-16
CVE-2008-1814 [CRITICAL] CVE-2008-1814: Unspecified vulnerability in the Oracle Secure Enterprise Search or Ultrasearch component in Oracle Unspecified vulnerability in the Oracle Secure Enterprise Search or Ultrasearch component in Oracle Database 9.0.1.5 FIPS+, 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.3; Application Server 9.0.4.3 and 10.1.2.2; and Oracle Collaboration Suite 10.1.2; has unknown impact and remote attack vectors, aka DB04.
nvd
CVE-2022-21498P3MEDIUMCVSS 6.5v12.1.0.2v19c+1 more2022-04-19
CVE-2022-21498 [MEDIUM] CVE-2022-21498: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in unauthoriz
nvd
CVE-2019-2444P3HIGHCVSS 8.2v12.1.0.2v12.2.0.1+1 more2019-01-16
CVE-2019-2444 [HIGH] CVE-2019-2444: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human interaction from a perso
nvd
CVE-2017-10190P3HIGHCVSS 8.2v11.2.0.4v12.1.0.2+1 more2017-10-19
CVE-2017-10190 [HIGH] CVE-2017-10190: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Java VM executes to compromise Java VM. While the vulnerability is
nvd
CVE-2023-21829P3MEDIUMCVSS 6.3v19cv21c2023-01-18
CVE-2023-21829 [MEDIUM] CVE-2023-21829: Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported Vulnerability in the Oracle Database RDBMS Security component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database RDBMS Security. Successful attacks require human interact
nvd
CVE-2018-1288P4MEDIUMCVSS 5.4v11.2.0.4v12.1.0.2+3 more2018-07-26
CVE-2018-1288 [MEDIUM] CVE-2018-1288: In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authentic In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
nvd
CVE-2019-3740P4MEDIUMCVSS 6.5v12.1.0.2v12.2.0.1+2 more2019-09-18
CVE-2019-3740 [MEDIUM] CWE-310 CVE-2019-3740: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to an Information Exposure Through Timing Discrepancy vulnerabilities during DSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover DSA keys.
nvd
CVE-2019-3738P4MEDIUMCVSS 6.5v12.1.0.2v12.2.0.1+2 more2019-09-18
CVE-2019-3738 [MEDIUM] CWE-325 CVE-2019-3738: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step v RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to a Missing Required Cryptographic Step vulnerability. A malicious remote attacker could potentially exploit this vulnerability to coerce two parties into computing the same predictable shared key.
nvd
CVE-2019-3739P4MEDIUMCVSS 6.5v12.1.0.2v12.2.0.1+2 more2019-09-18
CVE-2019-3739 [MEDIUM] CWE-310 CVE-2019-3739: RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Dis RSA BSAFE Crypto-J versions prior to 6.2.5 are vulnerable to Information Exposure Through Timing Discrepancy vulnerabilities during ECDSA key generation. A malicious remote attacker could potentially exploit those vulnerabilities to recover ECDSA keys.
nvd
CVE-2017-10261P4MEDIUMCVSS 6.5v11.2.0.4v12.1.0.22017-10-19
CVE-2017-10261 [MEDIUM] CWE-200 CVE-2017-10261: Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are a Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where XML Database executes to compromise XML Database. While the vulnerability is in X
nvd
CVE-2016-0677P4MEDIUMCVSS 5.9v12.1.0.1v12.1.0.22016-04-21
CVE-2016-0677 [MEDIUM] CVE-2016-0677: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12. Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.
nvd
Oracle Database vulnerabilities | cvebase