Executive brief
A security vulnerability exists in the Oracle Database Server's RDBMS Security component. An attacker with existing low-level access to the server's underlying infrastructure could exploit this to view sensitive internal database information. While the impact is limited to unauthorized data reading, it could lead to the exposure of configuration or security-related details.
Technical details
This vulnerability (CWE-200) affects the RDBMS Security component of Oracle Database Server version 12.1.0.2. It is categorized as an information exposure flaw that is easily exploitable by an attacker with 'Local Logon' privileges on the infrastructure where the database executes. Successful exploitation requires no user interaction and allows the attacker to read a subset of data managed by the RDBMS Security component. Oracle addressed this issue in the January 2017 Critical Patch Update.
Affected products
- Oracle Database Server 12.1.0.2
Timeline
- 2017-01-27: advisory: NVD published the vulnerability details.
- 2017-01-27: patched: Oracle released the January 2017 Critical Patch Update.