CVE-2015-4863 is an unspecified vulnerability within the Portable Clusterware component of Oracle Database Server versions 11.2.0.4, 12.1.0.1, and 12.1.0.2. This critical vulnerability has a CVSS score of 10.0, indicating it can be exploited remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Despite its high severity and a FAUCET Risk Score of 83/100, there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed in the KEV catalog. Community discussion and media coverage are minimal, with only one article noting Oracle's patch for this and other flaws.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.2.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* | ||
12.1.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:12.1.0.1:*:*:*:*:*:*:* | ||
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.