CVE-2018-3259
Description
Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18c. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java VM. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H).
Risk Information
Base Score
9.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
4.946
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple Vulnerabilities are affected in Oracle 11.2.0.4 | Windows |
| Multiple Vulnerabilities are affected in Oracle 12.1.0.2 | Windows |
| Multiple Vulnerabilities are affected in Oracle 12.2.0.1 | Windows |
| Multiple Vulnerabilities are affected in Oracle 18c | Windows |
| Multiple Vulnerabilities are affected in Oracle Database Server 11.2.0.4 | Windows |
| Multiple Vulnerabilities are affected in Oracle Database Server 12.1.0.2 | Windows |
| Multiple Vulnerabilities are affected in Oracle Database Server 12.2.0.1 | Windows |
| Multiple Vulnerabilities are affected in Oracle Database Server 18c | Windows |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234