Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-2515

EPSS 0.35% · P57
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2020-2515

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Vulnerability in the Database Gateway for ODBC component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1, 18c and 19c. Difficult to exploit vulnerability allows low privileged attacker having Create Session privilege with network access via OracleNet to compromise Database Gateway for ODBC. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Database Gateway for ODBC accessible data as well as unauthorized read access to a subset of Database Gateway for ODBC accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Database Gateway for ODBC. CVSS 3.0 Base Score 5.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L).
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Title
Oracle Database Server 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Oracle Database Server是美国Oracle公司的一套关系数据库管理系统。该数据库管理系统提供数据管理、分布式处理等功能。Session是Oxen开源的一种新型的加密私人信使。 Oracle Database Server中的ODBC的Database Gateway组件中存在安全漏洞。攻击者可利用该漏洞未授权读取、更新、插入或删除数据,造成拒绝服务,影响数据的保密性、完整性和可用性。以下产品及版本受到影响:Oracle Database Server Database Gateway
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Oracle CorporationOracle Database 11.2.0.4 -

II. Public POCs for CVE-2020-2515

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2020-2515

登录查看更多情报信息。

Same Patch Batch · Oracle Corporation · 2020-01-15 · 203 CVEs total

CVE-2020-2667Oracle E-Business Suite 安全漏洞
CVE-2020-2655Oracle Java SE 安全漏洞
CVE-2020-2656Oracle Solaris 安全漏洞
CVE-2020-2657Oracle E-Business Suite 安全漏洞
CVE-2020-2658Oracle E-Business Suite 安全漏洞
CVE-2020-2659Oracle Java SE 安全漏洞
CVE-2020-2660Oracle MySQL 安全漏洞
CVE-2020-2661Oracle E-Business Suite iSupport 安全漏洞
CVE-2020-2662Oracle E-Business Suite iSupport 安全漏洞
CVE-2020-2663Oracle PeopleSoft Enterprise PeopleTools 安全漏洞
CVE-2020-2664Oracle Solaris 安全漏洞
CVE-2020-2665Oracle E-Business Suite 安全漏洞
CVE-2020-2666Oracle E-Business Suite 安全漏洞
CVE-2020-2677Oracle Hospitality Applications 安全漏洞
CVE-2020-2674Oracle Virtualization 安全漏洞
CVE-2020-2675Oracle Hospitality Applications 安全漏洞
CVE-2020-2676Oracle Hospitality Applications 安全漏洞
CVE-2020-2673Oracle Enterprise Manager Application Testing Suite 安全漏洞
CVE-2020-2678Oracle Virtualization VM VirtualBox 安全漏洞
CVE-2020-2679Oracle MySQL 安全漏洞

Showing top 20 of 203 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2020-2515

No comments yet


Leave a comment