Oracle Database vulnerabilities
64 known vulnerabilities affecting oracle/database.
Total CVEs
64
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
CRITICAL13HIGH16MEDIUM24LOW11
Vulnerabilities
Page 3 of 4
CVE-2019-2406HIGHCVSS 7.2v12.1.0.2v12.2.0.1+1 more2019-01-16
CVE-2019-2406 [HIGH] CVE-2019-2406: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can
nvd
CVE-2018-1288MEDIUMCVSS 5.4v11.2.0.4v12.1.0.2+3 more2018-07-26
CVE-2018-1288 [MEDIUM] CVE-2018-1288: In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authentic
In Apache Kafka 0.9.0.0 to 0.9.0.1, 0.10.0.0 to 0.10.2.1, 0.11.0.0 to 0.11.0.2, and 1.0.0, authenticated Kafka users may perform action reserved for the Broker via a manually created fetch request interfering with data replication, resulting in data loss.
nvd
CVE-2017-10321HIGHCVSS 8.8v11.2.0.4v12.1.0.2+1 more2017-10-19
CVE-2017-10321 [HIGH] CVE-2017-10321: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. While the vulnerability is in Core RD
nvd
CVE-2017-10190HIGHCVSS 8.2v11.2.0.4v12.1.0.2+1 more2017-10-19
CVE-2017-10190 [HIGH] CVE-2017-10190: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Java VM executes to compromise Java VM. While the vulnerability is
nvd
CVE-2017-10261MEDIUMCVSS 6.5v11.2.0.4v12.1.0.22017-10-19
CVE-2017-10261 [MEDIUM] CWE-200 CVE-2017-10261: Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are a
Vulnerability in the XML Database component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with logon to the infrastructure where XML Database executes to compromise XML Database. While the vulnerability is in X
nvd
CVE-2017-10292LOWCVSS 2.3v11.2.0.4v12.1.0.2+1 more2017-10-19
CVE-2017-10292 [LOW] CWE-269 CVE-2017-10292: Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are
Vulnerability in the RDBMS Security component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create User privilege with logon to the infrastructure where RDBMS Security executes to compromise RDBMS Security. Successful attacks o
nvd
CVE-2017-10202CRITICALCVSS 9.9v11.2.0.4v12.1.0.2+1 more2017-08-08
CVE-2017-10202 [CRITICAL] CVE-2017-10202: Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected
Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks
nvd
CVE-2017-3567MEDIUMCVSS 5.3v11.2.0.4v12.1.0.22017-04-24
CVE-2017-3567 [MEDIUM] CVE-2017-3567: Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected
Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. Successful attacks of this vulnerability can result in u
nvd
CVE-2017-3310CRITICALCVSS 9.0v11.2.0.4v12.1.0.22017-01-27
CVE-2017-3310 [CRITICAL] CVE-2017-3310: Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected
Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4 and 12.1.0.2. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. Successful attacks require human interaction from a pers
nvd
CVE-2016-5497MEDIUMCVSS 6.4v12.1.0.22016-10-25
CVE-2016-5497 [MEDIUM] CWE-284 CVE-2016-5497: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-5572MEDIUMCVSS 6.4v12.1.0.22016-10-25
CVE-2016-5572 [MEDIUM] CWE-264 CVE-2016-5572: Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows loca
Unspecified vulnerability in the Kernel PDB component in Oracle Database Server 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-2183HIGHCVSS 7.5v11.2.0.4v12.1.0.22016-09-01
CVE-2016-2183 [HIGH] CWE-200 CVE-2016-2183: The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and
The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a birthday bound of approximately four billion blocks, which makes it easier for remote attackers to obtain cleartext data via a birthday attack against a long-duration encrypted session, as demonstrated by an HTTPS session using Triple DE
nvd
CVE-2016-3609CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2016-07-21
CVE-2016-3609 [CRITICAL] CVE-2016-3609: Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12
Unspecified vulnerability in the OJVM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-3479HIGHCVSS 7.5v11.2.0.4v12.1.0.22016-07-21
CVE-2016-3479 [HIGH] CVE-2016-3479: Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 a
Unspecified vulnerability in the Portable Clusterware component in Oracle Database Server 11.2.0.4 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2016-3489MEDIUMCVSS 6.7v11.2.0.4v12.1.0.1+1 more2016-07-21
CVE-2016-3489 [MEDIUM] CVE-2016-3489: Unspecified vulnerability in the Data Pump Import component in Oracle Database Server 11.2.0.4, 12.1
Unspecified vulnerability in the Data Pump Import component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-3488MEDIUMCVSS 4.4v12.1.0.22016-07-21
CVE-2016-3488 [MEDIUM] CVE-2016-3488: Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows loc
Unspecified vulnerability in the DB Sharding component in Oracle Database Server 12.1.0.2 allows local users to affect integrity via unknown vectors.
nvd
CVE-2016-3484LOWCVSS 3.4v11.2.0.4v12.1.0.1+1 more2016-07-21
CVE-2016-3484 [LOW] CVE-2016-3484: Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.2.0.4, 12.1.0
Unspecified vulnerability in the Database Vault component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect confidentiality and integrity via unknown vectors.
nvd
CVE-2016-3454CRITICALCVSS 9.0v11.2.0.4v12.1.0.1+1 more2016-04-21
CVE-2016-3454 [CRITICAL] CVE-2016-3454: Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and
Unspecified vulnerability in the Java VM component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.
nvd
CVE-2016-0677MEDIUMCVSS 5.9v12.1.0.1v12.1.0.22016-04-21
CVE-2016-0677 [MEDIUM] CVE-2016-0677: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 12.1.0.1 and 12.1.0.2 allows remote attackers to affect availability via unknown vectors.
nvd
CVE-2016-0691LOWCVSS 3.3v11.2.0.4v12.1.0.1+1 more2016-04-21
CVE-2016-0691 [LOW] CVE-2016-0691: Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0
Unspecified vulnerability in the RDBMS Security component in Oracle Database Server 11.2.0.4, 12.1.0.1, and 12.1.0.2 allows local users to affect integrity via unknown vectors, a different vulnerability than CVE-2016-0690.
nvd