QID 20302

Date Published: 2022-12-01

QID 20302: Oracle Database 18c OJVM Critical Patch Update - October 2019

Oracle Database quarterly patches are proactive cumulative patches containing recommended bug fixes that are released on a regular schedule.

Affected Software:
Oracle Database 18c

QID Detection Logic (Authenticated):
Authentication via Oracle Database:
This QID reviews the Oracle output from the table name DBA_REGISTRY_SQLPATCH for patch information.

Successful exploitation could allow an attacker to compromise the database.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as Medium - 4.3 severity.
  • Solution
    Patch Availability for Oracle Database 18 - 18.8.0.0.191015, 18.7.1.0.191015, 18.6.2.0.191015
    Customers are requested to refer to CPUOCT2019 to obtain details about how to deploy the update.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    cpuoct2019 URL Logo www.oracle.com/security-alerts/cpuoct2019.html