Security News Critical vulnerability in Oracle Database, patch without delay!

LASER_oneXM

Level 37
Thread author
Verified
Top Poster
Well-known
Feb 4, 2016
2,520
Oracle is urging users to patch their Oracle Database installations to plug a critical security issue that can result in complete compromise of the Oracle Database and shell access to the underlying server.

About the vulnerability (CVE-2018-3110)

The vulnerability (CVE-2018-3110) affects Oracle Database versions 11.2.0.4 and 12.2.0.1 on Windows and is apparently easy to exploit, but can only be exploited remotely by an authenticated attacker.

The vulnerability is in the Java Virtual Machine component of Oracle Database Server. It requires no user interaction and allows attackers that have Create Session privilege with network access via Oracle Net to compromise the component.

“CVE-2018-3110 also affects Oracle Database version 12.1.0.2 on Windows as well as Oracle Database on Linux and Unix, however patches for those versions and platforms were included in the July 2018 CPU,” Oracle shared.
The fix, offered late last Friday, is not applicable to client-only installations, i.e., installations that do not have the Oracle Database Server installed.

“Due to the nature of this vulnerability, Oracle strongly recommends that customers take action without delay,” the company said, but did not mention whether it is being exploited in the wild or how the flaw was discovered.
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top