Patch Reviews - DB (MOSC)

MOSC Banner

Regarding Security alert CVE-2018-3110. Please can you clarify what versions of Oracle and platform

edited Aug 26, 2018 5:01AM in Patch Reviews - DB (MOSC) 1 commentAnswered

The text of the security note is very vague.  See bold text below.  Please can you clarify what Oracle versions on Linux are affected.

This Security Alert addresses an Oracle Database vulnerability in versions 11.2.0.4 and 12.2.0.1 on Windows. CVE-2018-3110 has a CVSS v3 base score of 9.9, and can result in complete compromise of the Oracle Database and shell access to the underlying server. CVE-2018-3110 also affects Oracle Database version 12.1.0.2 on Windows as well as Oracle Database on Linux and Unix, however patches for those versions and platforms were included in the July 2018 CPU.

Also,  does the vulnerability only affect databases with the JVM component installed? 

Howdy, Stranger!

Log In

To view full details, sign in to My Oracle Support Community.

Register

Don't have a My Oracle Support Community account? Click here to get started.

Category Leaderboard

Top contributors this month

New to My Oracle Support Community? Visit our Welcome Center

MOSC Help Center