CVE-2017-10202
Vulnerability in the OJVM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows low privileged attacker having Create Session, Create Procedure privilege with network access via multiple protocols to compromise OJVM. While the vulnerability is in OJVM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of OJVM. Note: This score is for Windows platforms. On non-Windows platforms Scope is Unchanged, giving a CVSS Base Score of 8.8. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
EPSS 2.14% · 84.5th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Oracle Corporation | Oracle Database | 11.2.0.4, 12.1.0.2, 12.2.0.1 |
| oracle | database | 11.2.0.4, 12.1.0.2, 12.2.0.1 |
Exploit Intelligence
- Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) (github-poc)
- Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) (github-poc)
- Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) (github-poc)
- Simplified Version of Cryptography Attack based on Birthday Paradox: Sweet32 (CVE-2016-2183) (github-poc)
- Test code for poodle attack (CVE-2014-3566) (github-poc)
- Test code for poodle attack (CVE-2014-3566) (github-poc)
- Test code for poodle attack (CVE-2014-3566) (github-poc)
- Test code for poodle attack (CVE-2014-3566) (github-poc)
- uthrasri/openssl_g2.5_CVE-2014-3566 (github-poc)
- uthrasri/openssl_g2.5_CVE-2014-3566 (github-poc)
…and 25 more exploits
Timeline
- Jun 20, 2016 PoC Published
- Jul 19, 2017 CVE Published
- Jul 20, 2018 PoC Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 6, 2022 EPSS Score