CVE-2018-2913 is a critical vulnerability in the Monitoring Manager subcomponent of Oracle GoldenGate versions 12.1.2.1.0, 12.2.0.2.0, and 12.3.0.1.0. This easily exploitable vulnerability allows an unauthenticated attacker with network access via TCP to compromise Oracle GoldenGate, potentially leading to a complete takeover of the system and significant impact on additional products. With a CVSS 3.0 Base Score of 10.0, it carries the highest severity, indicating full confidentiality, integrity, and availability impacts. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion with 11 mentions and one media article, suggesting awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:goldengate:12.1.2.1.0:*:*:*:*:*:*:* | ||
12.2.0.2.0CPE matchmatch criteria | cpe:2.3:a:oracle:goldengate:12.2.0.2.0:*:*:*:*:*:*:* | ||
12.3.0.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:goldengate:12.3.0.1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] Multiple Oracle GoldenGate Manager Vulnerabilities
Oct 17, 2018[R1] Multiple Oracle GoldenGate Manager Vulnerabilities
Oct 17, 2018[R1] Multiple Oracle GoldenGate Manager Vulnerabilities
Oct 17, 2018