Learn about CVE-2017-10202, a critical vulnerability in Oracle Database Server's OJVM component affecting versions 11.2.0.4, 12.1.0.2, and 12.2.0.1. Understand the impact, exploitation mechanism, and mitigation steps.
A vulnerability in the OJVM component of Oracle Database Server affecting versions 11.2.0.4, 12.1.0.2, and 12.2.0.1, allowing attackers to compromise OJVM and potentially impact other products.
Understanding CVE-2017-10202
This CVE identifies a critical vulnerability in Oracle Database Server's OJVM component, with significant implications for system security.
What is CVE-2017-10202?
The vulnerability in the OJVM component of Oracle Database Server affects versions 11.2.0.4, 12.1.0.2, and 12.2.0.1. It can be exploited by a low privileged attacker with specific privileges and network access, potentially leading to a complete takeover of the OJVM.
The Impact of CVE-2017-10202
Successful exploitation of this vulnerability can result in the compromise of the OJVM, potentially affecting the confidentiality, integrity, and availability of the system. The CVSS Base Score is 9.9, indicating a severe impact on security.
Technical Details of CVE-2017-10202
This section provides detailed technical information about the vulnerability.
Vulnerability Description
The vulnerability allows a low privileged attacker with Create Session and Create Procedure privileges and network access via multiple protocols to compromise the OJVM, potentially impacting other products as well.
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2017-10202 requires immediate actions and long-term security practices.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates