Oracle Database Server vulnerabilities
502 known vulnerabilities affecting oracle/database_server.
Total CVEs
502
CISA KEV
0
Public exploits
25
Exploited in wild
0
Severity breakdown
CRITICAL112HIGH71MEDIUM250LOW69
Vulnerabilities
Page 4 of 26
CVE-2019-2940LOWCVSS 2.3v12.1.0.2v12.2.0.1+1 more2019-10-16
CVE-2019-2940 [LOW] CVE-2019-2940: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Create Session privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks of this vulnerability can
nvd
CVE-2019-2955LOWCVSS 3.9v11.2.0.4v12.1.0.2+3 more2019-10-16
CVE-2019-2955 [LOW] CVE-2019-2955: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human
nvd
CVE-2019-2954LOWCVSS 3.9v11.2.0.4v12.1.0.2+3 more2019-10-16
CVE-2019-2954 [LOW] CVE-2019-2954: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful a
nvd
CVE-2019-16942CRITICALCVSS 9.8v12.2.0.1v18c+1 more2019-10-01
CVE-2019-16942 [CRITICAL] CWE-502 CVE-2019-16942: A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When D
A Polymorphic Typing issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.10. When Default Typing is enabled (either globally or for a specific property) for an externally exposed JSON endpoint and the service has the commons-dbcp (1.4) jar in the classpath, and an attacker can find an RMI service endpoint to access, it is possible
nvd
CVE-2019-2776HIGHCVSS 7.6v12.1.0.2v12.2.0.1+2 more2019-07-23
CVE-2019-2776 [HIGH] CVE-2019-2776: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Index privilege with network access via OracleNet to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may signifi
nvd
CVE-2019-2799HIGHCVSS 7.5v11.2.0.4v12.1.0.2+2 more2019-07-23
CVE-2019-2799 [HIGH] CVE-2019-2799: Vulnerability in the Oracle ODBC Driver component of Oracle Database Server<span class=font-red><b>
Vulnerability in the Oracle ODBC Driver component of Oracle Database Server ***PRIVILEGE CANNOT BE NONE FOR AUTHENTICATED ATTACKS***. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows low privileged attacker having None privilege with network access via multiple protocols to compromise Oracle
nvd
CVE-2019-2749MEDIUMCVSS 6.8v11.2.0.4v12.1.0.2+3 more2019-07-23
CVE-2019-2749 [MEDIUM] CVE-2019-2749: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vu
nvd
CVE-2019-2753MEDIUMCVSS 4.6v11.2.0.4v12.1.0.2+2 more2019-07-23
CVE-2019-2753 [MEDIUM] CVE-2019-2753: Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are af
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Oracle Text. Successful attacks require human interaction from a per
nvd
CVE-2019-2569MEDIUMCVSS 4.0v11.2.0.4v12.1.0.2+1 more2019-07-23
CVE-2019-2569 [MEDIUM] CVE-2019-2569: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Difficult to exploit vulnerability allows high privileged attacker having Local Logon privilege with logon to the infrastructure where Core RDBMS executes to compromise Core RDBMS. Successful attacks require human inte
nvd
CVE-2019-2484MEDIUMCVSS 5.4v5.1v18.22019-07-23
CVE-2019-2484 [MEDIUM] CVE-2019-2484: Vulnerability in the Application Express component of Oracle Database Server. Supported versions tha
Vulnerability in the Application Express component of Oracle Database Server. Supported versions that are affected are 5.1 and 18.2. Easily exploitable vulnerability allows low privileged attacker having Valid Account privilege with network access via HTTP to compromise Application Express. Successful attacks require human interaction from a person other than
nvd
CVE-2019-12973MEDIUMCVSS 5.5v18c2019-06-26
CVE-2019-12973 [MEDIUM] CVE-2019-12973: In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c.
In OpenJPEG 2.3.1, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted bmp file. This issue is similar to CVE-2018-6616.
nvd
CVE-2019-2517CRITICALCVSS 9.1v12.2.0.1v18c2019-04-23
CVE-2019-2517 [CRITICAL] CVE-2019-2517: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having DBFS_ROLE privilege with network access via Oracle Net to compromise Core RDBMS. While the vulnerability is in Core RDBMS, attacks may significantly impact add
nvd
CVE-2019-2516HIGHCVSS 8.2v11.2.0.4v12.1.0.2+2 more2019-04-23
CVE-2019-2516 [HIGH] CVE-2019-2516: Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions th
Vulnerability in the Portable Clusterware component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows high privileged attacker having Grid Infrastructure User privilege with logon to the infrastructure where Portable Clusterware executes to compromise Portable Cluste
nvd
CVE-2019-2518HIGHCVSS 7.5v11.2.0.4v12.1.0.2+3 more2019-04-23
CVE-2019-2518 [HIGH] CVE-2019-2518: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks of this vuln
nvd
CVE-2019-2582MEDIUMCVSS 5.3v12.2.0.1v18c2019-04-23
CVE-2019-2582 [MEDIUM] CVE-2019-2582: Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are aff
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Core RDBMS a
nvd
CVE-2019-2571MEDIUMCVSS 6.6v11.2.0.4v12.1.0.2+2 more2019-04-23
CVE-2019-2571 [MEDIUM] CVE-2019-2571: Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are
Vulnerability in the RDBMS DataPump component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Difficult to exploit vulnerability allows high privileged attacker having DBA role privilege with network access via Oracle Net to compromise RDBMS DataPump. Successful attacks of this vulnerability can result
nvd
CVE-2019-2547LOWCVSS 3.5v11.2.0.4v12.1.0.2+2 more2019-01-16
CVE-2019-2547 [LOW] CVE-2019-2547: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise Java VM. Successful attacks require human intera
nvd
CVE-2018-14719CRITICALCVSS 9.8v11.2.0.4v12.1.0.2+3 more2019-01-02
CVE-2018-14719 [CRITICAL] CWE-502 CVE-2018-14719: FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code b
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.
nvd
CVE-2018-1000873MEDIUMCVSS 6.5v12.1.0.2v12.2.0.1+2 more2018-12-20
CVE-2018-1000873 [MEDIUM] CWE-20 CVE-2018-1000873: Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in
Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerabilit
nvd
CVE-2018-3259CRITICALCVSS 9.8v11.2.0.4v12.1.0.2+2 more2018-10-17
CVE-2018-3259 [CRITICAL] CVE-2018-3259: Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affect
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.
nvd