A database server on 19C Enterprise which is affected by multiple vulnerabilities
There is a report came from our security teams. they find multiple vulnerabilities on Oracle databases which hosts on WINDOWS, not Linux. the solution is asking to apply critical patches 19.16 on the database, but the database is on patch 19.24 currently.
I will appreciate if anybody can provide me suggestions or solutions.
*********************
- Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that areaffected are 12.1.0.2 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access viaOracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a personother than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impactadditional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option.(CVE-2021-2351)