Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Oracle Text. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Text accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Text. CVSS 3.0 Base Score 4.6 (Confidentiality and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:N/A:L).
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Oracle Database Server Text组件访问控制错误漏洞
Vulnerability Description
Oracle Database Server是美国甲骨文(Oracle)公司的一套关系数据库管理系统。该数据库管理系统提供数据管理、分布式处理等功能。Core RDBMS是其中的一个关系型数据库核心组件。ODBC Driver是其中的一个开放式数据库连接(ODBC)驱动程序组件。 Oracle Database Server中的Text组件存在安全漏洞。攻击者可利用该漏洞未授权读取数据,造成拒绝服务, 影响数据的保密性和可用性。以下产品及版本受到影响:Oracle Database Server 11.2
CVSS Information
N/A
Vulnerability Type
N/A