CVE-2021-2103 — Oracle Complex Maintenance Repair AND Overhaul vulnerability

7 documents7 sources
Severity
8.2HIGHNVD
EPSS
1.6%
top 18.29%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 20
Latest updateFeb 27

Description

Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box). Supported versions that are affected are 11.5.10, 12.1 and 12.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Complex Maintenance, Repair, and Overhaul. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Oracle Complex Maintenance, Repair…

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:NExploitability: 2.8 | Impact: 4.7

Affected Packages1 packages

â–¶NVDoracle/complex_maintenance_repair_and_overhaul11.5.10, 12.1, 12.2+2

🔴Vulnerability Details

3
GHSA
GHSA-625v-hxfr-pr86: Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box)↗2022-05-24
â–¶
CVEList
CVE-2021-2103: Vulnerability in the Oracle Complex Maintenance, Repair, and Overhaul product of Oracle Supply Chain (component: Dialog Box)↗2021-01-20
â–¶
Project0
Project Zero RCA: CVE-2020-15999: FreeType Heap Buffer Overflow in Load_SBit_Png↗
â–¶

📋Vendor Advisories

2
Microsoft
Windows Admin Center Security Feature Bypass Vulnerability↗2021-03-09
â–¶
Oracle
Oracle Oracle Supply Chain Risk Matrix: Dialog Box — CVE-2021-2103↗2021-01-15
â–¶

💬Community

1
Bugzilla
CVE-2021-46933 kernel: usb: gadget: f_fs: Clear ffs_eventfd in ffs_data_clear.↗2024-02-27
â–¶
CVE-2021-2103 — Oracle vulnerability | cvebase