CVE-2021-2351
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.6 / Impact: 5.9
Source: NVD (Secondary)
Description
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected (248)
Products: Oracle: Advanced Networking Option, Agile Engineering Data Management, Agile Plm, Agile Product Lifecycle Management For Process, Airlines Data Model, Application Performance Management, Application Testing Suite, Argus Analytics, Argus Insight, Argus Mart, Argus Safety, Banking Apis, Banking Digital Experience, Banking Enterprise Default Management, Banking Platform, Big Data Spatial And Graph, Blockchain Platform, Clinical, Commerce Platform, Communications Application Session Controller, Communications Billing And Revenue Management, Communications Calendar Server, Communications Contacts Server, Communications Convergent Charging Controller, Communications Data Model, Communications Design Studio, Communications Diameter Intelligence Hub, Communications Ip Service Activator, Communications Metasolv Solution, Communications Network Charging And Control, Communications Network Integrity, Communications Pricing Design Center, Communications Services Gatekeeper, Communications Session Report Manager, Communications Session Route Manager, Data Integrator, Demantra Demand Management, Documaker, Enterprise Data Quality, Enterprise Manager Base Platform, Enterprise Manager Ops Center, Financial Services Analytical Applications Infrastructure, Financial Services Behavior Detection Platform, Financial Services Enterprise Case Management, Financial Services Foreign Account Tax Compliance Act Management, Financial Services Model Management And Governance, Financial Services Trade Based Anti Money Laundering, Flexcube Investor Servicing, Flexcube Private Banking, Fusion Middleware, Goldengate, Goldengate Application Adapters, Graph Server And Client, Health Sciences Clinical Development Analytics, Health Sciences Inform Crf Submit, Health Sciences Information Manager, Healthcare Data Repository, Healthcare Foundation, Healthcare Translational Research, Hospitality Inventory Management, Hospitality Opera 5, Hospitality Reporting And Analytics, Hospitality Suite8, Hyperion Infrastructure Technology, Ilearning, Instantis Enterprisetrack, Insurance Data Gateway, Insurance Insbridge Rating And Underwriting, Insurance Policy Administration, Insurance Rules Palette, Jd Edwards Enterpriseone Tools, Oss Support Tools, Peoplesoft Enterprise Peopletools, Policy Automation, Primavera Analytics, Primavera Data Warehouse, Primavera Gateway, Primavera P6 Enterprise Project Portfolio Management, Primavera P6 Professional Project Management, Primavera Unifier, Product Lifecycle Analytics, Rapid Planning, Real User Experience Insight, Retail Analytics, Retail Assortment Planning, Retail Back Office, Retail Central Office, Retail Customer Insights, Retail Extract Transform And Load, Retail Financial Integration, Retail Integration Bus, Retail Merchandising System, Retail Order Broker, Retail Order Management System, Retail Point Of Service, Retail Predictive Application Server, Retail Price Management, Retail Returns Management, Retail Service Backbone, Retail Store Inventory Management, Retail Xstore Point Of Service, Siebel Ui Framework, Spatial Studio, Storagetek Acsls, Storagetek Tape Analytics, Thesaurus Management System, Timesten In Memory Database, Utilities Framework, Utilities Testing Accelerator, Weblogic Server, Zfs Storage Application Integration Engineering Software
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 12.1.0.2 | |
| Version 6.2.1.0 | |
| Version 9.3.6 | |
| Version 6.2.2.0 | |
| Version 12.1.1.0.0 | |
| Version 13.4.1.0 | |
| Version 13.3.0.1 | |
| Version 8.2.1 | |
| Version 8.2.1 | |
| Version 8.2.1 | |
| Version 8.2.1 | |
| From 18.1 to 18.3 | |
| From 18.1 to 18.3 | |
| Version 2.10.0 | |
| Version 2.12.0 | |
| Before 23.1 | |
| Version 21.1.2 | |
| Version 5.2.1 | |
| Version 11.3.0 | |
| Version 3.9.0 | |
| Version 12.0.0.4 | |
| Version 8.0.0.5.0 | |
| Version 8.0.0.3.0 | |
| From 12.0.1.0.0 to 12.0.4.0.0 | |
| Version 11.3.2.1.0 | |
| Version 7.3.5 | |
| From 8.0.0 to 8.2.3 | |
| Version 7.4.0 | |
| Version 6.3.1 | |
| From 12.0.1.0 to 12.0.4.0.0 | |
| Version 7.3.5 | |
| Version 12.0.0.4 | |
| Version 7.0 | |
| From 8.0.0 to 8.2.5.0 | |
| From 8.2.0 to 8.2.5 | |
| Version 12.2.1.3.0 | |
| From 12.2.6 to 12.2.11 | |
| From 12.6.2 to 12.6.4 | |
| Version 12.2.1.3.0 | |
| Version 13.4.0.0 | |
| Version 12.4.0.0 | |
| From 8.0.7 to 8.1.1 | |
| Version 8.0.11 | |
| Version 8.0.11 | |
| Version 8.0.11 | |
| From 8.0.8.0.0 to 8.1.1.0.0 | |
| Version 8.0.7 | |
| Version 12.0.4 | |
| Version 12.0.0 | |
| Version 12.2.1.3.0 | |
| Before 12.3.0.1.0 | |
| Before 23.1 | |
| Before 21.4.0 | |
| Version 4.0.1 | |
| Version 6.2.1 | |
| Version 3.0.2 | |
| Version 7.0.2 | |
| From 7.3.0 to 7.3.0.2 | |
| Version 4.1.0 | |
| Before 9.1.0 | |
| Version 5.6 | |
| Version 9.1.0 | |
| Version 8.10.2 | |
| Version 11.2.7.0 | |
| Version 6.2 | |
| Version 17.1 | |
| Version 11.0.2 | |
| From 5.4 to 5.6.0 | |
| Version 11.0.2 | |
| Version 11.0.2 | |
| Version 9.2.6.3 | |
| Before 2.12.42 | |
| Version 8.57 | |
| From 12.2.0 to 12.2.24 | |
| Version 18.8.3.3 | |
| Version 18.8.3.3 | |
| From 17.12.0 to 17.12.11 | |
| From 17.12.0.0 to 17.12.20 | |
| From 17.12 to 17.12.20.0 | |
| From 17.7 to 17.12 | |
| Version 3.6.1 | |
| From 12.2.6 to 12.2.11 | |
| Version 13.4.1.0 | |
| From 16.0.0 to 16.0.2 | |
| Version 16.0.3 | |
| Version 14.1 | |
| Version 14.1 | |
| From 16.0 to 16.0.2 | |
| Version 13.2.8 | |
| Version 14.1.3.2 | |
| Version 14.1.3.2 | |
| Version 19.0.1 | |
| Version 16.0 | |
| Version 19.5 | |
| Version 14.1 | |
| Version 14.1.3 | |
| Version 14.1 | |
| Version 14.1 | |
| Version 14.1.3.2 | |
| Version 14.1 | |
| Version 17.0.4 | |
| Up to 21.12 | |
| Before 21.2.1 | |
| Version 8.5.1 | |
| Version 2.4 | |
| Version 5.2.3 | |
| Before 21.1.1.1.0 | |
| From 4.3.0.1.0 to 4.3.0.6.0 | |
| Version 6.0.0.1.1 | |
| Version 12.2.1.3.0 | |
| Version 1.3.3 |
Related CWEs
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CWE-384
Session Fixation
Authenticating a user, or otherwise establishing a new user session, without invalidating any existing session identifier gives an attacker the opportunity to steal authenticated sessions.
References (20)
Source: secalert_us@oracle.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert_us@oracle.com
ExploitMailing ListThird Party Advisory
Source: secalert_us@oracle.com
ExploitMailing ListThird Party Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: secalert_us@oracle.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.