QID 20296

Date Published: 2022-12-01

QID 20296: Oracle Database 18c Critical OJVM Patch Update - January 2019

Oracle Database quarterly patches are proactive cumulative patches containing recommended bug fixes that are released on a regular schedule.

Affected Software:
Oracle Database 18c

QID Detection Logic (Authenticated):
Authentication via Oracle Database:
This QID reviews the Oracle output from the table name DBA_REGISTRY_SQLPATCH for patch information.

Successful exploitation could allow an attacker to compromise the database.

  • CVSS V3 rated as Critical - 8.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Patch Availability for Oracle Database 18 - 18.5.0, 18.4.1, 18.3.2
    Customers are requested to refer to CPUJAN2019 to obtain details about how to deploy the update.
    Vendor References

    CVEs related to QID 20296

    Software Advisories
    Advisory ID Software Component Link
    cpujan2019 URL Logo www.oracle.com/security-alerts/cpujan2019.html