Back

CVE-2018-3110

CRITICAL

A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

Published: Aug 10, 2018 Modified: Jun 17, 2026
NVD-CWE-noinfo

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: LOW User Interaction: NONE Scope: CHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Affected Products (4)

Vendor Product Version
oracle database_server 11.2.0.4
oracle database_server 12.1.0.2
oracle database_server 12.2.0.1
oracle database_server 18

GitHub Security Advisory GHSA-q4vg-pwpq-j6r8

A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported...

Risk Scores

CVSS Score 9.9 / 10
EPSS Score 2.48%

Top 17% most likely to be exploited

Threat Score 40.3 / 100

Data Sources

NVD EPSS GitHub