CVE-2021-2015
published 2021-01-20CVE-2021-2015: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.10. Easily…
PriorityP343high8.2CVSS 3.1
AVNACLPRNUIRSCCHILAN
EPSS
1.17%
63.9th percentile
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Workflow, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data as well as unauthorized update, insert or delete access to some of Oracle Workflow accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| devise-two-factor | devise-two-factor | >= 0 < 4.0.2 | 4.0.2 |
| oracle | data_integrator | — | — |
| oracle | data_integrator | — | — |
| oracle | enterprise_manager_ops_center | — | — |
| oracle | workflow | 12.2.3 – 12.2.10 | — |
| oracle_corporation | workflow | — | — |
CVSS provenance
nvdv3.18.2HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
nvdv2.05.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:N
ghsa10.0CRITICAL
vendor_oracle8.2HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8ww5-7wc7-5j2j: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist)
ghsa_unreviewed·2022-05-24
CVE-2021-2015 [HIGH] GHSA-8ww5-7wc7-5j2j: Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist)
Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that are affected are 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Workflow. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Workflow, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Workflow accessible data as well as unauthorized update, insert or delete access to some of Oracle Workflow accessible data. CVSS 3.1 Base Score 8.2 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3
GHSA
OpenNMS Horizon vulnerable to XSS
ghsa·2022-05-24
CVE-2021-25934 [MEDIUM] CWE-79 OpenNMS Horizon vulnerable to XSS
OpenNMS Horizon vulnerable to XSS
In OpenNMS Horizon, versions opennms-18.0.0-1 through opennms-27.1.0-1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.7-1 are vulnerable to Stored Cross-Site Scripting, since the function `createRequisitionedNode()` does not perform any validation checks on the input sent to the `node-label` parameter. Due to this flaw an attacker could inject an arbitrary script which will be stored in the database.
GHSA
Improper one time password handling in devise-two-factor
ghsa·2022-04-07·CVSS 5.3
CVE-2021-43177 [MEDIUM] Improper one time password handling in devise-two-factor
Improper one time password handling in devise-two-factor
### Impact
As a result of an incomplete fix for CVE-2015-7225, in versions of devise-two-factor prior to 4.0.2 it is possible to reuse a One-Time-Password (OTP) for one (and only one) immediately trailing interval.
### Patches
This vulnerability has been patched in version 4.0.2 which was released on March 24th, 2022. Individuals using this package are strongly encouraged to upgrade as soon as possible.
### Credit for discovery
Benoit Côté-Jodoin
Michael Nipper - https://github.com/tinfoil/devise-two-factor/issues/106
GHSA
Deserialization of Untrusted Data in Log4j 1.x
ghsa·2022-01-21·CVSS 7.5
CVE-2022-23302 [HIGH] CWE-502 Deserialization of Untrusted Data in Log4j 1.x
Deserialization of Untrusted Data in Log4j 1.x
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-4104. Note this issue only affects Log4j 1.x when specifically configured to use JMSSink, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
GHSA
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
ghsa·2021-12-14·CVSS 10.0
CVE-2021-4104 [CRITICAL] CWE-502 JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in a similar fashion to CVE-2021-44228. Note this issue only affects Log4j 1.2 when specifically configured to use JMSAppender, which is not the default. Apache Log4j 1.2 reached end of life in August 2015. Users should upgrade to Log4j 2 as it addresses numerous other issues from the previous versions.
GHSA
Improper Check for Unusual or Exceptional Conditions in json-smart
ghsa·2021-06-16
CVE-2021-27568 [MEDIUM] CWE-754 Improper Check for Unusual or Exceptional Conditions in json-smart
Improper Check for Unusual or Exceptional Conditions in json-smart
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
GHSA
Cross-Site Request Forgery in OpenNMS Horizon
ghsa·2021-05-25
CVE-2021-25931 [HIGH] CWE-352 Cross-Site Request Forgery in OpenNMS Horizon
Cross-Site Request Forgery in OpenNMS Horizon
In OpenNMS Horizon, versions opennms-1-0-stable through opennms-27.1.1; OpenNMS Meridian, versions meridian-foundation-2015.1.0-1 through meridian-foundation-2019.1.18-1; meridian-foundation-2020.1.0-1 through meridian-foundation-2020.1.6-1 are vulnerable to CSRF, due to no CSRF protection at `/opennms/admin/userGroupView/users/updateUser`. This flaw allows assigning `ROLE_ADMIN` security role to a normal user. Using this flaw, an attacker can trick the admin user to assign administrator privileges to a normal user by enticing him to click upon an attacker-controlled website.
Palo Alto
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-09-04·CVSS 6.0
CVE-2022-22965 [MEDIUM] PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0008 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2010-1622, CVE-2015-7552, CVE-2018-16840, CVE-2019-7639, CVE-2020-17049, CVE-2020-7774, CVE-2021-0131, CVE-2021-0132, CVE-2021-0133, CVE-2021-0134, CVE-2021-4044, CVE-2021-4160, CVE-2021-41773, CVE-2022-1343, CVE-2022-21449, CVE-2022-2274, CVE-2022-22963, CVE-2022-22965, CVE-2022-24697, CVE-2022-32207, CVE-2022-3358, CVE-2022-3996, CVE-2022-40664, CVE-2022-44792, CVE-2022-44793, CVE-2023-1255, CVE-2023-22809, CVE-2023-23919, CVE-2023-3341, CVE-2023-4236, CVE-2023-4863, CVE-2023-51767
Affected products: PAN-OS
Red Hat
kernel: btrfs: use latest_dev in btrfs_show_devname
vendor_redhat·2024-06-19·CVSS 4.7
CVE-2021-47599 [MEDIUM] CWE-362 kernel: btrfs: use latest_dev in btrfs_show_devname
kernel: btrfs: use latest_dev in btrfs_show_devname
In the Linux kernel, the following vulnerability has been resolved:
btrfs: use latest_dev in btrfs_show_devname
The test case btrfs/238 reports the warning below:
WARNING: CPU: 3 PID: 481 at fs/btrfs/super.c:2509 btrfs_show_devname+0x104/0x1e8 [btrfs]
CPU: 2 PID: 1 Comm: systemd Tainted: G W O 5.14.0-rc1-custom #72
Hardware name: QEMU QEMU Virtual Machine, BIOS 0.0.0 02/06/2015
Call trace:
btrfs_show_devname+0x108/0x1b4 [btrfs]
show_mountinfo+0x234/0x2c4
m_show+0x28/0x34
seq_read_iter+0x12c/0x3c4
vfs_read+0x29c/0x2c8
ksys_read+0x80/0xec
__arm64_sys_read+0x28/0x34
invoke_syscall+0x50/0xf8
do_el0_svc+0x88/0x138
el0_svc+0x2c/0x8c
el0t_64_sync_handler+0x84/0xe4
el0t_64_sync+0x198/0x19c
Reason:
While btrfs_prepare_sprout() moves the fs_device
Red Hat
kernel: tpm: efi: Use local variable for calculating final log size
vendor_redhat·2024-02-27·CVSS 5.5
CVE-2021-46951 [MEDIUM] CWE-191 kernel: tpm: efi: Use local variable for calculating final log size
kernel: tpm: efi: Use local variable for calculating final log size
In the Linux kernel, the following vulnerability has been resolved:
tpm: efi: Use local variable for calculating final log size
When tpm_read_log_efi is called multiple times, which happens when
one loads and unloads a TPM2 driver multiple times, then the global
variable efi_tpm_final_log_size will at some point become a negative
number due to the subtraction of final_events_preboot_size occurring
each time. Use a local variable to avoid this integer underflow.
The following issue is now resolved:
Mar 8 15:35:12 hibinst kernel: Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015
Mar 8 15:35:12 hibinst kernel: Workqueue: tpm-vtpm vtpm_proxy_work [tpm_vtpm_proxy]
Mar 8 15:35:12 hibinst kernel: RIP: 001
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Tools (Apache Standard Taglibs) — CVE-2015-0254
vendor_oracle·2021-07-15·CVSS 7.3
CVE-2015-0254 [HIGH] Oracle Oracle Fusion Middleware Risk Matrix: Third Party Tools (Apache Standard Taglibs) — CVE-2015-0254
Oracle Oracle Fusion Middleware Risk Matrix: Third Party Tools (Apache Standard Taglibs) vulnerability
CVE: CVE-2015-0254
CVSS: 7.3
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
Red Hat
json-smart: uncaught exception may lead to crash or information disclosure
vendor_redhat·2021-02-23·CVSS 5.9
CVE-2021-27568 [MEDIUM] CWE-200 json-smart: uncaught exception may lead to crash or information disclosure
json-smart: uncaught exception may lead to crash or information disclosure
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
A flaw was found in json-smart. When an exception is thrown from a function, but is not caught, the program using the library may crash or expose sensitive information. The highest threat from this vulnerability is to data confidentiality and system availability.
In OpenShift Container Platform (OCP), the Hive/Presto/Hadoop components that comprise the OCP Metering stack, ship the vulnerable version of json-smar
Oracle
Oracle Oracle E-Business Suite Risk Matrix: Worklist — CVE-2021-2015
vendor_oracle·2021-01-15·CVSS 8.2
CVE-2021-2015 [HIGH] Oracle Oracle E-Business Suite Risk Matrix: Worklist — CVE-2021-2015
Oracle Oracle E-Business Suite Risk Matrix: Worklist vulnerability
CVE: CVE-2021-2015
CVSS: 8.2
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
No detection rules found.
Bugzilla
CVE-2021-47242 kernel: mptcp: fix soft lookup in subflow_error_report()
bugzilla·2024-05-22·CVSS 7.8
CVE-2021-47242 [HIGH] CVE-2021-47242 kernel: mptcp: fix soft lookup in subflow_error_report()
CVE-2021-47242 kernel: mptcp: fix soft lookup in subflow_error_report()
In the Linux kernel, the following vulnerability has been resolved:
mptcp: fix soft lookup in subflow_error_report()
The Linux kernel CVE team has assigned CVE-2021-47242 to this issue.
Upstream advisory:
https://lore.kernel.org/linux-cve-announce/2024052142-CVE-2021-47242-2015@gregkh/T
Bugzilla
CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosure
bugzilla·2021-03-17·CVSS 5.9
CVE-2021-27568 [MEDIUM] CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosure
CVE-2021-27568 json-smart: uncaught exception may lead to crash or information disclosure
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
Upstream Reference:
https://github.com/netplex/json-smart-v1/issues/7
https://github.com/netplex/json-smart-v2/issues/60
Discussion:
A word on scoring, our scoring is currently 9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H and NVD of 9.1/CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H will change to 5.9/CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
My take:
Exploitability Metrics:
Attack Vect
Krebs
Kaseya Left Customer Portal Vulnerable to 2015 Flaw in its Own Software
blogs_krebs·2021-07-08·CVSS 4.0
[MEDIUM] Kaseya Left Customer Portal Vulnerable to 2015 Flaw in its Own Software
Last week cybercriminals deployed ransomware to 1,500 organizations, including many that provide IT security and technical support to other companies. The attackers exploited a vulnerability in software from Kaseya , a Miami-based company whose products help system administrators manage large networks remotely. Now it appears Kaseya’s customer service portal was left vulnerable until last week to a data-leaking security flaw that was first identified in the same software six years ago.
On July 3, the REvil ransomware affiliate program began using a zero-day security hole ( CVE-2021-30116 ) to deploy ransomware to hundreds of IT management companies running Kaseya’s remote management software — known as the Kaseya Virtual System Administrator (VSA).
According to this entry for CVE-2021-30
2021-01-20
Published