PatchSiren cyber security CVE debrief
CVE-2017-3240 Oracle CVE debrief
CVE-2017-3240 is a low-severity Oracle Database Server issue in the RDBMS Security component affecting Oracle Database Server 12.1.0.2. According to the NVD record, a low-privileged attacker with local logon access on the infrastructure where RDBMS Security executes could compromise that component and obtain unauthorized read access to a subset of RDBMS Security-accessible data. The CVSS v3.0 base score is 3.3, with confidentiality impact only.
- Vendor
- Oracle
- Product
- CVE-2017-3240
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle Database administrators, security teams managing hosts that run Oracle Database Server 12.1.0.2, and operators who allow local logon access on database infrastructure.
Technical summary
The supplied NVD data classifies the flaw as CVE-200 with CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. That means the attack requires local access and low privileges, has no user interaction, and results in limited confidentiality impact without integrity or availability impact. The vulnerable CPE in the corpus is oracle:database_server:12.1.0.2.
Defensive priority
Low to moderate. It is not a remote, high-impact flaw, but it still merits patching on affected Oracle Database Server 12.1.0.2 systems, especially where local logon access is available to untrusted or multi-user operators.
Recommended defensive actions
- Review Oracle's January 2017 Critical Patch Update advisory for the affected release and apply the vendor fix for Database Server 12.1.0.2.
- Confirm whether Oracle Database Server 12.1.0.2 is deployed on any host that permits local logon access by non-administrators.
- Restrict local access to database hosts and limit who can log on where RDBMS Security executes.
- Verify that compensating controls and routine patch management cover Oracle CPU advisories for database infrastructure.
- Track the CVE in vulnerability management, but treat it as a lower-priority item than remotely exploitable or integrity-impacting issues.
Evidence notes
This debrief is based only on the supplied NVD record and Oracle advisory reference in the corpus. The CVE was published on 2017-01-27T22:59:02.303Z; the NVD record was later modified on 2026-05-13T00:24:29.033Z, which is record maintenance timing and not the vulnerability's original disclosure date. The corpus lists Oracle's CPU January 2017 advisory as the vendor patch reference and identifies Oracle Database Server 12.1.0.2 as vulnerable.
Official resources
-
CVE-2017-3240 CVE record
CVE.org
-
CVE-2017-3240 NVD detail
NVD
-
Source item URL
nvd_modified
-
Mitigation or vendor reference
[email protected] - Patch, Vendor Advisory
- Source reference
- Source reference
Publicly disclosed on 2017-01-27 via the CVE/NVD record. The supplied corpus also includes a later NVD modification timestamp of 2026-05-13, which should not be treated as the issue date.