CVE-2019-2547 is a low-severity vulnerability in the Java VM component of Oracle Database Server, affecting versions 11.2.0.4, 12.1.0.2, 12.2.0.1, and 18c. An attacker with low privileges and network access can exploit this vulnerability, requiring user interaction, to cause a partial denial of service. The CVSS 3.0 Base Score is 3.5, indicating a low impact on availability. Exploitation requires human interaction from a person other than the attacker, and successful attacks can lead to a partial denial of service of the Java VM. The vulnerability is easily exploitable with low privileges and network access. There is no evidence of active exploitation, nor are there any public exploit codes available on platforms like Metasploit or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.2.0.4CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:11.2.0.4:*:*:*:*:*:*:* | ||
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:12.1.0.2:*:*:*:*:*:*:* | ||
12.2.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:database_server:12.2.0.1:*:*:*:*:*:*:* | ||
18cCPE matchmatch criteria | cpe:2.3:a:oracle:database_server:18c:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.