SB2021101925 - Multiple vulnerabilities in Oracle Database Server
Published: October 19, 2021
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 8 secuirty vulnerabilities.
1) Improper input validation (CVE-ID: CVE-2021-35576)
The vulnerability allows a remote privileged user to manipulate data.
The vulnerability exists due to improper input validation within the Oracle Database Enterprise Edition Unified Audit in Oracle Database Server. A remote privileged user can exploit this vulnerability to manipulate data.
2) Improper input validation (CVE-ID: CVE-2021-35558)
The vulnerability allows a remote authenticated user to perform service disruption.
The vulnerability exists due to improper input validation within the Core RDBMS in Oracle Database Server. A remote authenticated user can exploit this vulnerability to perform service disruption.
3) Improper input validation (CVE-ID: CVE-2021-35557)
The vulnerability allows a remote authenticated user to perform service disruption.
The vulnerability exists due to improper input validation within the Core RDBMS in Oracle Database Server. A remote authenticated user can exploit this vulnerability to perform service disruption.
4) Improper input validation (CVE-ID: CVE-2021-35551)
The vulnerability allows a remote privileged user to damange or delete data.
The vulnerability exists due to improper input validation within the RDBMS Security in Oracle Database Server. A remote privileged user can exploit this vulnerability to damange or delete data.
5) Improper input validation (CVE-ID: CVE-2021-2332)
The vulnerability allows a remote privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Oracle LogMiner in Oracle Database Server. A remote privileged user can exploit this vulnerability to execute arbitrary code.
6) Improper input validation (CVE-ID: CVE-2021-35619)
The vulnerability allows a remote authenticated user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Java VM in Oracle Database Server. A remote authenticated user can exploit this vulnerability to execute arbitrary code.
7) Resource management error (CVE-ID: CVE-2021-25122)
The vulnerability allows a remote attacker to gain access to sensitive information.
The vulnerability exists due to improper management of internal resources within the application when processing new h2c connection requests. A remote attacker can send specially crafted requests to the server and obtain contents of HTTP responses, served to other users.
8) Improper input validation (CVE-ID: CVE-2021-35599)
The vulnerability allows a local privileged user to execute arbitrary code.
The vulnerability exists due to improper input validation within the Zero Downtime DB Migration to Cloud in Oracle Database Server. A local privileged user can exploit this vulnerability to execute arbitrary code.
Remediation
Install update from vendor's website.