CVE-2019-2406 is a critical vulnerability in the Oracle Database Server's Core RDBMS component, affecting versions 12.1.0.2, 12.2.0.1, and 18c. This easily exploitable flaw allows a highly privileged attacker with Create Session and Execute Catalog Role privileges, and network access via Oracle Net, to compromise the Core RDBMS. A successful attack can lead to a complete takeover of the database, impacting confidentiality, integrity, and availability. With a CVSS v3.0 score of 7.2 (High), this vulnerability has a low EPSS score and no known public exploits, Metasploit modules, or community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:database:12.1.0.2:*:*:*:*:*:*:* | ||
12.2.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:database:12.2.0.1:*:*:*:*:*:*:* | ||
18cCPE matchmatch criteria | cpe:2.3:a:oracle:database:18c:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.