8.3

CVE-2021-2351

Exploit

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OracleAdvanced Networking Option Version12.1.0.2
OracleAdvanced Networking Option Version12.2.0.1
OracleAgile Plm Version9.3.6
OracleAirlines Data Model Version12.1.1.0.0
OracleAirlines Data Model Version12.2.0.1.0
OracleApplication Testing Suite Version13.3.0.1
OracleArgus Analytics Version8.2.1
OracleArgus Analytics Version8.2.2
OracleArgus Analytics Version8.2.3
OracleArgus Insight Version8.2.1
OracleArgus Insight Version8.2.2
OracleArgus Insight Version8.2.3
OracleArgus Mart Version8.2.1
OracleArgus Mart Version8.2.2
OracleArgus Mart Version8.2.3
OracleArgus Safety Version8.2.1
OracleArgus Safety Version8.2.2
OracleArgus Safety Version8.2.3
OracleBanking Apis Version >= 18.1 <= 18.3
OracleBanking Apis Version19.1
OracleBanking Apis Version19.2
OracleBanking Apis Version20.1
OracleBanking Apis Version21.1
OracleBanking Digital Experience Version >= 18.1 <= 18.3
OracleBanking Platform Version2.6.2
OracleBanking Platform Version2.7.1
OracleBanking Platform Version2.12.0
OracleBlockchain Platform Version21.1.2
OracleClinical Version5.2.1
OracleClinical Version5.2.2
OracleCommerce Platform Version11.3.0
OracleCommerce Platform Version11.3.1
OracleCommerce Platform Version11.3.2
OracleCommunications Calendar Server Version8.0.0.5.0
OracleCommunications Contacts Server Version8.0.0.3.0
OracleCommunications Convergent Charging Controller Version >= 12.0.1.0.0 <= 12.0.4.0.0
OracleCommunications Data Model Version11.3.2.1.0
OracleCommunications Data Model Version11.3.2.2.0
OracleCommunications Data Model Version11.3.2.3.0
OracleCommunications Data Model Version12.1.0.1.0
OracleCommunications Data Model Version12.1.2.0.0
OracleCommunications Diameter Intelligence Hub Version >= 8.0.0 <= 8.2.3
OracleCommunications Network Charging And Control Version >= 12.0.1.0 <= 12.0.4.0.0
OracleCommunications Session Report Manager Version >= 8.0.0 <= 8.2.5.0
OracleCommunications Session Route Manager Version >= 8.2.0 <= 8.2.5
OracleData Integrator Version12.2.1.3.0
OracleData Integrator Version12.2.1.4.0
OracleDemantra Demand Management Version >= 12.2.6 <= 12.2.11
OracleDocumaker Version >= 12.6.2 <= 12.6.4
OracleDocumaker Version12.6.0
OracleDocumaker Version12.7.0
OracleEnterprise Data Quality Version12.2.1.3.0
OracleEnterprise Data Quality Version12.2.1.4.0
OracleFinancial Services Model Management And Governance Version >= 8.0.8.0.0 <= 8.1.1.0.0
OracleFinancial Services Trade-based Anti Money Laundering Version8.0.7 SwEditionenterprise
OracleFinancial Services Trade-based Anti Money Laundering Version8.0.8 SwEditionenterprise
OracleFlexcube Private Banking Version12.0.0
OracleFlexcube Private Banking Version12.1.0
OracleFusion Middleware Version12.2.1.3.0
OracleFusion Middleware Version12.2.1.4.0
OracleGoldengate Version < 12.3.0.1.0
OracleGoldengate Version >= 19.1.0.0.1 < 21.5.0.0.220118
OracleGraph Server And Client Version < 21.4.0
OracleHealthcare Foundation Version >= 7.3.0 <= 7.3.0.2
OracleHealthcare Foundation Version >= 8.0.0 <= 8.0.2
OracleHealthcare Foundation Version >= 8.1.0 <= 8.1.1
OracleHospitality Opera 5 Version5.6
OracleHospitality Suite8 Version8.10.2
OracleHospitality Suite8 Version8.11.0
OracleHospitality Suite8 Version8.12.0
OracleHospitality Suite8 Version8.13.0
OracleHospitality Suite8 Version8.14.0
OracleIlearning Version6.2
OracleIlearning Version6.3
OracleInsurance Data Gateway Version11.0.2
OracleInsurance Data Gateway Version11.1.0
OracleInsurance Data Gateway Version11.2.7
OracleInsurance Data Gateway Version11.3.0
OracleInsurance Data Gateway Version11.3.1
OracleInsurance Rules Palette Version11.0.2
OracleInsurance Rules Palette Version11.1.0
OracleInsurance Rules Palette Version11.2.7
OracleInsurance Rules Palette Version11.3.0
OracleInsurance Rules Palette Version11.3.1
OracleOss Support Tools Version < 2.12.42
OraclePolicy Automation Version >= 12.2.0 <= 12.2.24
OraclePrimavera Analytics Version18.8.3.3
OraclePrimavera Analytics Version19.12.11.1
OraclePrimavera Analytics Version20.12.12.0
OraclePrimavera Data Warehouse Version18.8.3.3
OraclePrimavera Data Warehouse Version19.12.11.1
OraclePrimavera Data Warehouse Version20.12.12.0
OraclePrimavera Gateway Version >= 17.12.0 <= 17.12.11
OraclePrimavera Gateway Version >= 18.8.0 <= 18.8.12
OraclePrimavera Gateway Version >= 19.12.0 <= 19.12.11
OraclePrimavera Gateway Version >= 20.12.0 <= 20.12.7
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 17.12.0.0 <= 17.12.20
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 19.12.0.0 <= 19.12.17.0
OraclePrimavera P6 Enterprise Project Portfolio Management Version >= 20.12.0.0 <= 20.12.9.0
OraclePrimavera P6 Professional Project Management Version >= 17.12 <= 17.12.20.0
OraclePrimavera P6 Professional Project Management Version >= 18.8 <= 18.8.24.0
OraclePrimavera P6 Professional Project Management Version >= 19.12.0.0 <= 19.12.17.0
OraclePrimavera P6 Professional Project Management Version >= 20.12.0.0 <= 20.12.9.0
OraclePrimavera Unifier Version >= 17.7 <= 17.12
OraclePrimavera Unifier Version18.8
OraclePrimavera Unifier Version19.12
OraclePrimavera Unifier Version20.12
OraclePrimavera Unifier Version21.12
OracleRapid Planning Version >= 12.2.6 <= 12.2.11
OracleReal User Experience Insight Version13.4.1.0
OracleReal User Experience Insight Version13.5.1.0
OracleRetail Analytics Version >= 16.0.0 <= 16.0.2
OracleRetail Back Office Version14.1
OracleRetail Central Office Version14.1
OracleRetail Customer Insights Version >= 16.0 <= 16.0.2
OracleRetail Financial Integration Version14.1.3.2
OracleRetail Financial Integration Version15.0.3.1
OracleRetail Financial Integration Version16.0.3.0
OracleRetail Integration Bus Version14.1.3.2
OracleRetail Integration Bus Version15.0.3.1
OracleRetail Integration Bus Version16.0.3
OracleRetail Integration Bus Version19.0.1
OracleRetail Order Broker Version16.0
OracleRetail Order Broker Version18.0
OracleRetail Order Broker Version19.1
OracleRetail Service Backbone Version14.1.3.2
OracleRetail Service Backbone Version15.0.3.1
OracleRetail Service Backbone Version16.0.3
OracleRetail Service Backbone Version19.0.1
OracleSiebel Ui Framework Version <= 21.12
OracleSpatial Studio Version < 21.2.1
OracleStoragetek Acsls Version8.5.1
OracleTimesten In-memory Database Version < 21.1.1.1.0
OracleTimesten In-memory Database Version21.1.1.1.0
OracleUtilities Framework Version >= 4.3.0.1.0 <= 4.3.0.6.0
OracleUtilities Framework Version4.2.0.3.0
OracleUtilities Framework Version4.4.0.0.0
OracleUtilities Framework Version4.4.0.2.0
OracleUtilities Framework Version4.4.0.3.0
OracleUtilities Testing Accelerator Version6.0.0.1.1
OracleUtilities Testing Accelerator Version6.0.0.2.2
OracleUtilities Testing Accelerator Version6.0.0.3.1
OracleWeblogic Server Version12.2.1.3.0
OracleWeblogic Server Version12.2.1.4.0
OracleWeblogic Server Version14.1.1.0.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.54% 0.872
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
nvd@nist.gov 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
secalert_us@oracle.com 8.3 1.6 6
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
CWE-327 Use of a Broken or Risky Cryptographic Algorithm

The product uses a broken or risky cryptographic algorithm or protocol.

CWE-384 Session Fixation

Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.