Executive brief
A critical vulnerability exists in the Java component (OJVM) of Oracle Database Server, which is used to run Java applications within the database. A low-privileged user could exploit this flaw to take full control of the database environment, potentially leading to the theft or destruction of sensitive corporate data. While the attack requires some interaction from another user, a successful breach could spread beyond the database to impact other connected business systems.
Technical details
This vulnerability affects the Oracle Java VM (OJVM) component within Oracle Database Server versions 11.2.0.4 and 12.1.0.2. It is classified as an easily exploitable flaw that requires the attacker to have 'Create Session' and 'Create Procedure' privileges. The attack is delivered over a network via multiple protocols but requires human interaction from a person other than the attacker (UI:R) to succeed. Because the vulnerability has a 'Changed' scope (S:C), a successful exploit allows the attacker to move beyond the OJVM sandbox to impact the underlying database and potentially additional products, resulting in a complete loss of confidentiality, integrity, and availability. Oracle addressed this in the January 2017 Critical Patch Update.
Affected products
- Oracle Database Server 11.2.0.4, 12.1.0.2
Timeline
- 2017-01-27: disclosed
- 2017-01-27: advisory: Oracle January 2017 Critical Patch Update