CVE-2021-2110
published 2021-01-20CVE-2021-2110: Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters). The supported version that is affected is 8.2.2…
PriorityP425medium5CVSS 3.1
AVNACLPRLUINSCCLINAN
EPSS
0.91%
55.9th percentile
Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. While the vulnerability is in Oracle Argus Safety, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Argus Safety accessible data. CVSS 3.1 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | office_app | — | — |
| oracle | argus_safety | — | — |
| oracle_corporation | argus_safety | — | — |
CVSS provenance
nvdv3.15.0MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
vendor_msrc9.6CRITICAL
vendor_oracle5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Microsoft Office app Remote Code Execution Vulnerability
vendor_msrc·2021-12-14·CVSS 9.6
CVE-2021-43905 [CRITICAL] Microsoft Office app Remote Code Execution Vulnerability
Microsoft Office app Remote Code Execution Vulnerability
FAQ: How do I get the update for Office app?
The Microsoft Store will automatically update affected customers. Alternatively, customers can get the update immediately; see here for details. Be sure to select the tab for the operating system installed on your device to search for updates.
It is possible for customers to disable automatic updates for the Microsoft Store. The Microsoft Store will not automatically install this update for those customers. You can get the update through the store here: ms-windows-store://pdp/?productid=9WZDNCRD29V9.
How can I check if the update is installed?
App versions 18.2110.13110.0 and later contain this update.
FAQ: Is the Preview Pane an attack vector for this vulnerability?
No, the Preview Pane
Oracle
Oracle Oracle Health Sciences Applications Risk Matrix: Letters — CVE-2021-2110
vendor_oracle·2021-01-15·CVSS 5.0
CVE-2021-2110 [MEDIUM] Oracle Oracle Health Sciences Applications Risk Matrix: Letters — CVE-2021-2110
Oracle Oracle Health Sciences Applications Risk Matrix: Letters vulnerability
CVE: CVE-2021-2110
CVSS: 5.0
Protocol: HTTP
Remote exploit: No
Affected versions: Network
Advisory: cpujan2021 (JAN 2021)
GHSA
GHSA-9p74-pqx9-3mrw: Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters)
ghsa_unreviewed·2022-05-24
CVE-2021-2110 [MEDIUM] GHSA-9p74-pqx9-3mrw: Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters)
Vulnerability in the Oracle Argus Safety product of Oracle Health Sciences Applications (component: Letters). The supported version that is affected is 8.2.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Argus Safety. While the vulnerability is in Oracle Argus Safety, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Argus Safety accessible data. CVSS 3.1 Base Score 5.0 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-01-20
Published