{"$ref":"https://www.cert.ssi.gouv.fr/openapi.json","affected_systems":[{"description":"Oracle Database Server version 11.2.0.4 sans le dernier correctif","product":{"name":"Database Server","vendor":{"name":"Oracle","scada":false}}},{"description":"Oracle Application Express de Oracle Database Server versions 5.1 \u00e0 19.2 sans le dernier correctif","product":{"name":"Database Server","vendor":{"name":"Oracle","scada":false}}},{"description":"Oracle Database Server version 12.1.0.2 sans le dernier correctif","product":{"name":"Database Server","vendor":{"name":"Oracle","scada":false}}},{"description":"Oracle Database Server version 19c sans le dernier correctif","product":{"name":"Database Server","vendor":{"name":"Oracle","scada":false}}},{"description":"Oracle Database Server version 18c sans le dernier correctif","product":{"name":"Database Server","vendor":{"name":"Oracle","scada":false}}},{"description":"Oracle Database Server version 12.2.0.1 sans le dernier correctif","product":{"name":"Database Server","vendor":{"name":"Oracle","scada":false}}}],"affected_systems_content":null,"content":"## Solution\n\nSe r\u00e9f\u00e9rer au bulletin de s\u00e9curit\u00e9 de l'\u00e9diteur pour l'obtention des\ncorrectifs (cf. section Documentation).\n","cves":[{"name":"CVE-2020-2975","url":"https://www.cve.org/CVERecord?id=CVE-2020-2975"},{"name":"CVE-2020-2969","url":"https://www.cve.org/CVERecord?id=CVE-2020-2969"},{"name":"CVE-2020-2973","url":"https://www.cve.org/CVERecord?id=CVE-2020-2973"},{"name":"CVE-2019-13990","url":"https://www.cve.org/CVERecord?id=CVE-2019-13990"},{"name":"CVE-2020-2513","url":"https://www.cve.org/CVERecord?id=CVE-2020-2513"},{"name":"CVE-2016-9843","url":"https://www.cve.org/CVERecord?id=CVE-2016-9843"},{"name":"CVE-2020-2974","url":"https://www.cve.org/CVERecord?id=CVE-2020-2974"},{"name":"CVE-2019-16943","url":"https://www.cve.org/CVERecord?id=CVE-2019-16943"},{"name":"CVE-2018-18314","url":"https://www.cve.org/CVERecord?id=CVE-2018-18314"},{"name":"CVE-2020-8112","url":"https://www.cve.org/CVERecord?id=CVE-2020-8112"},{"name":"CVE-2020-2971","url":"https://www.cve.org/CVERecord?id=CVE-2020-2971"},{"name":"CVE-2020-2972","url":"https://www.cve.org/CVERecord?id=CVE-2020-2972"},{"name":"CVE-2020-2976","url":"https://www.cve.org/CVERecord?id=CVE-2020-2976"},{"name":"CVE-2016-1000031","url":"https://www.cve.org/CVERecord?id=CVE-2016-1000031"},{"name":"CVE-2019-17569","url":"https://www.cve.org/CVERecord?id=CVE-2019-17569"},{"name":"CVE-2020-2978","url":"https://www.cve.org/CVERecord?id=CVE-2020-2978"},{"name":"CVE-2019-10086","url":"https://www.cve.org/CVERecord?id=CVE-2019-10086"},{"name":"CVE-2020-2977","url":"https://www.cve.org/CVERecord?id=CVE-2020-2977"},{"name":"CVE-2020-2968","url":"https://www.cve.org/CVERecord?id=CVE-2020-2968"}],"links":[],"reference":"CERTFR-2020-AVI-433","revisions":[{"description":"Version initiale","revision_date":"2020-07-15T00:00:00.000000"}],"risks":[{"description":"Atteinte \u00e0 l'int\u00e9grit\u00e9 des donn\u00e9es"},{"description":"Contournement de la politique de s\u00e9curit\u00e9"},{"description":"Atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es"},{"description":"\u00c9l\u00e9vation de privil\u00e8ges"}],"summary":"De multiples vuln\u00e9rabilit\u00e9s ont \u00e9t\u00e9 d\u00e9couvertes dans Oracle Database\nServer. Certaines d'entre elles permettent \u00e0 un attaquant de provoquer\nun contournement de la politique de s\u00e9curit\u00e9, une atteinte \u00e0 l'int\u00e9grit\u00e9\ndes donn\u00e9es et une atteinte \u00e0 la confidentialit\u00e9 des donn\u00e9es.\n\nLes CVE suivantes sont r\u00e9f\u00e9renc\u00e9es mais l'\u00e9diteur indique qu'elles ne\nsont pas exploitables : CVE-2018-18314, CVE-2019-10086, CVE-2019-13990,\nCVE-2019-16943.\n","title":"Multiples vuln\u00e9rabilit\u00e9s dans Oracle Database Server","vendor_advisories":[{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Oracle d\u00e9taill\u00e9 cpujul2020 du 14 juillet 2020","url":"https://www.oracle.com/security-alerts/cpujul2020verbose.html#DB"},{"published_at":null,"title":"Bulletin de s\u00e9curit\u00e9 Oracle cpujul2020 du 14 juillet 2020","url":"https://www.oracle.com/security-alerts/cpujul2020.html"}]}
