New! Vulnerability Priority Rating (VPR)
Tenable calculates a dynamic VPR for every vulnerability. VPR combines vulnerability information with threat intelligence and machine learning algorithms to predict which vulnerabilities are most likely to be exploited in attacks. Read more about what VPR is and how it's different from CVSS.
VPR Score: 6.5
Synopsis
A real-time data integration and replication application installed on the remote host is affected by multiple vulnerabilities.
Description
The version of Oracle GoldenGate installed on the remote host is affected by the following vulnerabilities as noted in the October 2018 CPU advisory :
- A denial of service (DoS) vulnerability exists in the manager component of GoldenGate. An unauthenticated, remote attacker can exploit this by sending a malformed command via TCP, to cause the application to stop responding. (CVE-2018-2912, CVE-2018-2914)
- A stack-based buffer overflow condition exists in the manager component of GoldenGate. An unauthenticated, remote attacker can exploit this by sending a malformed command via TCP, to cause a denial of service condition or the execution of arbitrary code. (CVE-2018-2913)
Solution
Apply the appropriate patch according to the October 2018 Oracle Critical Patch Update advisory.