Input validation error in Oracle Database Server - CVE-2019-2619

 

Input validation error in Oracle Database Server - CVE-2019-2619

Published: July 21, 2022


Vulnerability identifier: #VU65645
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2619
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise Portable Clusterware.

The vulnerability exists in the Portable Clusterware component of Oracle Database Server. A local user with Grid Infrastructure User privilege can pass specially crafted input to the application and compromise Portable Clusterware.


Affected software

Oracle Database Server
IBM Security Verify Information Queue

How to mitigate CVE-2019-2619

Install updates from vendor's website.

IBM Security Verify Information Queue - update to 10.0.3

External References

Related Security Bulletins