Vulnerability in the RDBMS Sharding component of Oracle Database Server. Supported versions that are affected are 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Create Any View, Create Any Trigger privilege with network access via Oracle Net to compromise RDBMS Sharding. Successful attacks of this vulnerability can result in takeover of RDBMS Sharding. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
References
Link | Resource |
---|---|
https://www.oracle.com/security-alerts/cpujan2021.html | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-083/ | Third Party Advisory |
https://www.oracle.com/security-alerts/cpujan2021.html | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-083/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:02
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.oracle.com/security-alerts/cpujan2021.html - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-21-083/ - Third Party Advisory |
Information
Published : 2021-01-20 15:15
Updated : 2024-11-21 06:02
NVD link : CVE-2021-2054
Mitre link : CVE-2021-2054
CVE.ORG link : CVE-2021-2054
JSON object : View
Products Affected
oracle
- rdbms_sharding
CWE