Oracle Database Server Bugs Let Remote Authenticated Users Gain Elevated Privileges and Access Data and Local Users Modify Data and Deny Service
|
SecurityTracker Alert ID: 1041299 |
SecurityTracker URL: http://securitytracker.com/id/1041299
|
CVE Reference:
CVE-2018-2939, CVE-2018-3004, CVE-2018-3110
(Links to External Site)
|
Updated: Aug 21 2018
|
Original Entry Date: Jul 17 2018
|
Impact:
Denial of service via local system, Disclosure of system information, Disclosure of user information, Modification of system information, Modification of user information, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 11.2.0.4, 12.1.0.2, 12.2.0.1, 18.1, 18.2
|
Description:
Several vulnerabilities were reported in Oracle Database. A remote authenticated user can gain elevated privileges on the target system. A remote authenticated user can access data on the target system. A local user can cause denial of service conditions on the target system. A local user can modify data on the target system.
A local user can exploit a flaw in the Core RDBMS component to modify data and cause denial of service conditions [CVE-2018-2939].
A remote authenticated user can exploit a flaw in the Java VM component to access data [CVE-2018-3004].
A remote authenticated user can exploit a flaw in the Java VM component to gain elevated privileges [CVE-2018-3110].
Rich Mirch reported one vulnerability.
|
Impact:
A remote authenticated user can obtain elevated privileges on the target system.
A remote authenticated user can obtain data on the target system.
A local user can cause denial of service conditions on the target system.
A local user can modify data on the target system.
|
Solution:
The vendor has issued a fix as part of the July 2018 Critical Patch Update.
[Editor's note: The fix for CVE-2018-3110 applies to version 11.2.0.4 and 12.2.0.1 for Linux/Unix. For Windows-based systems, the fix for CVE-2018-3110 is described in Alert ID 1041531.]
The vendor advisories are available at:
http://www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html
http://www.oracle.com/technetwork/security-advisory/alert-cve-2018-3110-5032149.html
|
Vendor URL: www.oracle.com/technetwork/security-advisory/cpujul2018-4258247.html (Links to External Site)
|
Cause:
Not specified
|
Underlying OS: Linux (Any), UNIX (AIX), UNIX (HP/UX), UNIX (Solaris - SunOS), UNIX (Tru64), Windows (2003), Windows (2008), Windows (2012)
|
|
Message History:
None.
|
Source Message Contents
|
|
[Original Message Not Available for Viewing]
|
|