CVE-2021-35619 PUBLISHED CVSS 7.099999904632568 HIGH

Vulnerability in the Java VM component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Difficult to exploit vulnerability allows low privileged attacker having Create Procedure privilege with network access via Oracle Net to compromise Java VM. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.1 Base Score 7.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H).

EPSS 1.18% · 78.6th percentile

Risk Scores

CVSS v3.1
7.099999904632568
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score
1.18%
78.6th percentile

Affected Products

VendorProductVersions
oraclejava_virtual_machine21c, 12.1.0.2, 12.2.0.1
Oracle CorporationDatabase - Enterprise Edition12.2.0.1, 19c, *

Timeline

References

Open in Interactive Console →