The Latest in IT Security

Critical vulnerability in Oracle Database, patch without delay!

13
Aug
2018
Critical vulnerability in Oracle Database, patch without delay!

oracle-red

Oracle is urging users to patch their Oracle Database installations to plug a critical security issue that can result in complete compromise of the Oracle Database and shell access to the underlying server.

About the vulnerability (CVE-2018-3110)

The vulnerability (CVE-2018-3110) affects Oracle Database versions 11.2.0.4 and 12.2.0.1 on Windows and is apparently easy to exploit, but can only be exploited remotely by an authenticated attacker.

The vulnerability is in the Java Virtual Machine component of Oracle Database Server. It requires no user interaction and allows attackers that have Create Session privilege with network access via Oracle Net to compromise the component.

Read More

Leave a reply


Categories

MONDAY, SEPTEMBER 24, 2018

Featured

Archives

Latest Comments

Social Networks