Oracle Database vulnerabilities
64 known vulnerabilities affecting oracle/database.
Total CVEs
64
CISA KEV
0
Public exploits
3
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH16MEDIUM24LOW11
Vulnerabilities
Page 3 of 4
CVE-2020-5359P4MEDIUMCVSS 5.8v12.1.0.2v12.2.0.1+2 more2020-12-16
CVE-2020-5359 [MEDIUM] CWE-544 CVE-2020-5359: Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value V
Dell BSAFE Micro Edition Suite, versions prior to 4.5, are vulnerable to an Unchecked Return Value Vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to modify and corrupt the encrypted data.
nvd
CVE-2022-21411P4MEDIUMCVSS 5.4v12.1.0.2v19c+1 more2022-04-19
CVE-2022-21411 [MEDIUM] CVE-2022-21411: Vulnerability in the RDBMS Gateway / Generic ODBC Connectivity component of Oracle Database Server.
Vulnerability in the RDBMS Gateway / Generic ODBC Connectivity component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise RDBMS Gateway / Generic ODBC Connectivity. Successf
nvd
CVE-2021-35551P4MEDIUMCVSS 5.5v12.2.0.1v19c+1 more2021-10-20
CVE-2021-35551 [MEDIUM] CVE-2021-35551: Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are
Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized abi
nvd
CVE-2016-3489P4MEDIUMCVSS 6.7v11.2.0.4v12.1.0.1+1 more2016-07-21
CVE-2016-3489 [MEDIUM] CVE-2016-3489: Unspecified vulnerability in the Data Pump Import component in Oracle Database Server 11.2.0.4, 12.1
Unspecified vulnerability in the Data Pump Import component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2020-14901P4MEDIUMCVSS 4.9v19c2020-10-21
CVE-2020-14901 [MEDIUM] CVE-2020-14901: Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that
Vulnerability in the RDBMS Security component of Oracle Database Server. The supported version that is affected is 19c. Easily exploitable vulnerability allows high privileged attacker having Analyze Any privilege with network access via Oracle Net to compromise RDBMS Security. Successful attacks of this vulnerability can result in unauthorized access to cri
nvd
CVE-2016-5572P4MEDIUMCVSS 6.4v12.1.0.22016-10-25
CVE-2016-5572 [MEDIUM] CWE-264 CVE-2016-5572: Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows loca
Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-5497P4MEDIUMCVSS 6.4v12.1.0.22016-10-25
CVE-2016-5497 [MEDIUM] CWE-284 CVE-2016-5497: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2017-3567P4MEDIUMCVSS 5.3v11.2.0.4v12.1.0.22017-04-24
CVE-2017-3567 [MEDIUM] CVE-2017-3567: Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected
Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. Successful attacks of this vulnerability can result in u
nvd
CVE-2010-0076P4MEDIUMCVSS 6.0v3.2.1.00.102010-01-13
CVE-2010-0076 [MEDIUM] CVE-2010-0076: Unspecified vulnerability in the Application Express Application Builder component in Oracle Databas
Unspecified vulnerability in the Application Express Application Builder component in Oracle Database 3.2.1.00.10 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2021-35557P4MEDIUMCVSS 4.3v12.1.0.2v12.2.0.1+2 more2021-10-20
CVE-2021-35557 [MEDIUM] CVE-2021-35557: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2021-35558P4MEDIUMCVSS 4.3v12.1.0.2v12.2.0.1+2 more2021-10-20
CVE-2021-35558 [MEDIUM] CVE-2021-35558: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauth
nvd
CVE-2023-21827P4MEDIUMCVSS 4.3v19cv21c2023-01-18
CVE-2023-21827 [MEDIUM] CVE-2023-21827: Vulnerability in the Oracle Database Data Redaction component of Oracle Database Server. Supported
Vulnerability in the Oracle Database Data Redaction component of Oracle Database Server. Supported versions that are affected are 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database Data Redaction. Successful attacks of this vulnerability
nvd
CVE-2020-2978P4MEDIUMCVSS 4.1v12.1.0.2v12.2.0.1+2 more2020-07-15
CVE-2020-2978 [MEDIUM] CVE-2020-2978: Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Suppo
Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA role account privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition. While
nvd
CVE-2021-2334P4LOWCVSS 3.5v12.1.0.2v12.2.0.1+1 more2021-07-21
CVE-2021-2334 [LOW] CVE-2021-2334: Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Databas
Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Dat
nvd
CVE-2016-3488P4MEDIUMCVSS 4.4v12.1.0.22016-07-21
CVE-2016-3488 [MEDIUM] CVE-2016-3488: Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows loc
Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows local users to affect integrity via unknown vectors.
nvd
CVE-2021-2335P4LOWCVSS 3.5v12.1.0.2v12.2.0.1+1 more2021-07-21
CVE-2021-2335 [LOW] CVE-2021-2335: Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Databas
Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Dat
nvd
CVE-2021-2336P4LOWCVSS 3.5v12.1.0.2v12.2.0.1+1 more2021-07-21
CVE-2021-2336 [LOW] CVE-2021-2336: Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Databas
Vulnerability in the Oracle Database - Enterprise Edition Data Redaction component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Oracle Database - Enterprise Edition Dat
nvd
CVE-2016-0691P4LOWCVSS 3.3v11.2.0.4v12.1.0.1+1 more2016-04-21
CVE-2016-0691 [LOW] CVE-2016-0691: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690.
nvd
CVE-2016-0690P4LOWCVSS 3.3v11.2.0.4v12.1.0.1+1 more2016-04-21
CVE-2016-0690 [LOW] CVE-2016-0690: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0691.
nvd
CVE-2016-3484P4LOWCVSS 3.4v11.2.0.4v12.1.0.1+1 more2016-07-21
CVE-2016-3484 [LOW] CVE-2016-3484: Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.2.0.4, 12.1.0
Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality and integrity via unknown vectors.
nvd