PatchSiren

PatchSiren cyber security CVE debrief

CVE-2017-3240 Oracle CVE debrief

CVE-2017-3240 is a low-severity Oracle Database Server issue in the RDBMS Security component affecting Oracle Database Server 12.1.0.2. According to the NVD record, a low-privileged attacker with local logon access on the infrastructure where RDBMS Security executes could compromise that component and obtain unauthorized read access to a subset of RDBMS Security-accessible data. The CVSS v3.0 base score is 3.3, with confidentiality impact only.

Vendor
Oracle
Product
Database Server
CVSS
LOW 3.3
CISA KEV
Not listed in stored evidence
Original CVE published
2017-01-27
Original CVE updated
2026-05-13
Advisory published
2017-01-27
Advisory updated
2026-05-13

Who should care

Oracle Database administrators, security teams managing hosts that run Oracle Database Server 12.1.0.2, and operators who allow local logon access on database infrastructure.

Technical summary

The supplied NVD data classifies the flaw as CVE-200 with CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. That means the attack requires local access and low privileges, has no user interaction, and results in limited confidentiality impact without integrity or availability impact. The vulnerable CPE in the corpus is oracle:database_server:12.1.0.2.

Defensive priority

Low to moderate. It is not a remote, high-impact flaw, but it still merits patching on affected Oracle Database Server 12.1.0.2 systems, especially where local logon access is available to untrusted or multi-user operators.

Recommended defensive actions

  • Review Oracle's January 2017 Critical Patch Update advisory for the affected release and apply the vendor fix for Database Server 12.1.0.2.
  • Confirm whether Oracle Database Server 12.1.0.2 is deployed on any host that permits local logon access by non-administrators.
  • Restrict local access to database hosts and limit who can log on where RDBMS Security executes.
  • Verify that compensating controls and routine patch management cover Oracle CPU advisories for database infrastructure.
  • Track the CVE in vulnerability management, but treat it as a lower-priority item than remotely exploitable or integrity-impacting issues.

Evidence notes

This debrief is based only on the supplied NVD record and Oracle advisory reference in the corpus. The CVE was published on 2017-01-27T22:59:02.303Z; the NVD record was later modified on 2026-05-13T00:24:29.033Z, which is record maintenance timing and not the vulnerability's original disclosure date. The corpus lists Oracle's CPU January 2017 advisory as the vendor patch reference and identifies Oracle Database Server 12.1.0.2 as vulnerable.

Sources and references

Verified primary and authoritative sources

  • CVE-2017-3240 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2017-3240

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2017-3240 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3240

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.