Severity
7.3HIGH
EPSS
0.8%
top 26.79%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 22
Latest updateMay 24

Description

Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin). The supported version that is affected are 11.1.1.9 and 12.2.1.3 Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager for Fusion Middleware. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Enterprise Manager for Fusion Middleware a

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:LExploitability: 3.9 | Impact: 3.4

Affected Packages2 packages

NVDoracle/enterprise_manager11.1.1.9, 12.2.1.3+1

Patches

🔴Vulnerability Details

5
GHSA
GHSA-r688-j345-w6v4: Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin)2022-05-24
Kernel
Merge tag 'xfs-5.17-merge-5' of git://git.kernel.org/pub/scm/fs/xfs/xfs-linux2022-01-21
GHSA
RCE in H2 Console2022-01-06
CVEList
CVE-2021-2008: Vulnerability in the Enterprise Manager for Fusion Middleware product of Oracle Enterprise Manager (component: FMW Control Plugin)2021-04-22
GHSA
Misinterpretation of malicious XML input2021-03-12

💥Exploits & PoCs

2
Exploit-DB
Adobe ColdFusion 8 - Remote Command Execution (RCE)2021-06-24
Exploit-DB
Microworld eScan Server 9.0.742 - Directory Traversal2008-03-06

📋Vendor Advisories

2
Microsoft
Windows HTML Platforms Security Feature Bypass Vulnerability2021-06-08
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: FMW Control Plugin — CVE-2021-20082021-04-15
CVE-2021-2008 (HIGH CVSS 7.3) | Vulnerability in the Enterprise Man | cvebase.io