CVE-2018-3110 is a critical vulnerability in the Java VM component of Oracle Database Server, affecting versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18. This easily exploitable flaw allows a low-privileged attacker with Create Session privilege and network access via Oracle Net to compromise the Java VM. A successful attack can lead to a complete takeover of the Java VM, with significant impacts on confidentiality, integrity, and availability, reflected in its CVSS 3.0 Base Score of 9.9. While not listed in CISA KEV and lacking public exploit code in Metasploit or ExploitDB, it has garnered some community discussion and media coverage, indicating awareness of its severity.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.2.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* | ||
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* | ||
12.2.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:* | ||
18CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:18:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.