PatchSiren cyber security CVE debrief
CVE-2017-3240 Oracle CVE debrief
CVE-2017-3240 is a low-severity Oracle Database Server issue in the RDBMS Security component affecting Oracle Database Server 12.1.0.2. According to the NVD record, a low-privileged attacker with local logon access on the infrastructure where RDBMS Security executes could compromise that component and obtain unauthorized read access to a subset of RDBMS Security-accessible data. The CVSS v3.0 base score is 3.3, with confidentiality impact only.
- Vendor
- Oracle
- Product
- Database Server
- CVSS
- LOW 3.3
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2017-01-27
- Original CVE updated
- 2026-05-13
- Advisory published
- 2017-01-27
- Advisory updated
- 2026-05-13
Who should care
Oracle Database administrators, security teams managing hosts that run Oracle Database Server 12.1.0.2, and operators who allow local logon access on database infrastructure.
Technical summary
The supplied NVD data classifies the flaw as CVE-200 with CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N. That means the attack requires local access and low privileges, has no user interaction, and results in limited confidentiality impact without integrity or availability impact. The vulnerable CPE in the corpus is oracle:database_server:12.1.0.2.
Defensive priority
Low to moderate. It is not a remote, high-impact flaw, but it still merits patching on affected Oracle Database Server 12.1.0.2 systems, especially where local logon access is available to untrusted or multi-user operators.
Recommended defensive actions
- Review Oracle's January 2017 Critical Patch Update advisory for the affected release and apply the vendor fix for Database Server 12.1.0.2.
- Confirm whether Oracle Database Server 12.1.0.2 is deployed on any host that permits local logon access by non-administrators.
- Restrict local access to database hosts and limit who can log on where RDBMS Security executes.
- Verify that compensating controls and routine patch management cover Oracle CPU advisories for database infrastructure.
- Track the CVE in vulnerability management, but treat it as a lower-priority item than remotely exploitable or integrity-impacting issues.
Evidence notes
This debrief is based only on the supplied NVD record and Oracle advisory reference in the corpus. The CVE was published on 2017-01-27T22:59:02.303Z; the NVD record was later modified on 2026-05-13T00:24:29.033Z, which is record maintenance timing and not the vulnerability's original disclosure date. The corpus lists Oracle's CPU January 2017 advisory as the vendor patch reference and identifies Oracle Database Server 12.1.0.2 as vulnerable.
Sources and references
Verified primary and authoritative sources
-
CVE-2017-3240 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2017-3240
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2017-3240 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2017-3240
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.