Input validation error in Oracle Database Server - CVE-2019-2619
Published: July 21, 2022
Vulnerability identifier: #VU65645
CSH Severity: Low
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-2619
CWE-ID: CWE-20
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to compromise Portable Clusterware.
The vulnerability exists in the Portable Clusterware component of Oracle Database Server. A local user with Grid Infrastructure User privilege can pass specially crafted input to the application and compromise Portable Clusterware.
Affected software
Oracle Database Server
IBM Security Verify Information Queue
IBM Security Verify Information Queue
How to mitigate CVE-2019-2619
Install updates from vendor's website.
IBM Security Verify Information Queue - update to 10.0.3