CVE-2021-2332
published 2021-10-20CVE-2021-2332: Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily…
PriorityP434medium6.7CVSS 3.1
AVNACLPRHUINSUCLIHAH
EPSS
0.86%
54.4th percentile
Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle LogMiner. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle LogMiner accessible data as well as unauthorized read access to a subset of Oracle LogMiner accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle LogMiner. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H).
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle | database_server | — | — |
| oracle_corporation | database_enterprise_edition | — | — |
| oracle_corporation | database_enterprise_edition | — | — |
| oracle_corporation | database_enterprise_edition | — | — |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
vendor_oracle6.7MEDIUM
vendor_redhat3.3LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9gpg-wjp4-q3f9: Vulnerability in the Oracle LogMiner component of Oracle Database Server
ghsa_unreviewed·2022-05-24
CVE-2021-2332 [MEDIUM] GHSA-9gpg-wjp4-q3f9: Vulnerability in the Oracle LogMiner component of Oracle Database Server
Vulnerability in the Oracle LogMiner component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Oracle LogMiner. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle LogMiner accessible data as well as unauthorized read access to a subset of Oracle LogMiner accessible data and unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle LogMiner. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:H).
Red Hat
kernel: kfence: fix memory leak when cat kfence objects
vendor_redhat·2024-03-04·CVSS 3.3
CVE-2021-47089 [LOW] CWE-402 kernel: kfence: fix memory leak when cat kfence objects
kernel: kfence: fix memory leak when cat kfence objects
In the Linux kernel, the following vulnerability has been resolved:
kfence: fix memory leak when cat kfence objects
Hulk robot reported a kmemleak problem:
unreferenced object 0xffff93d1d8cc02e8 (size 248):
comm "cat", pid 23327, jiffies 4624670141 (age 495992.217s)
hex dump (first 32 bytes):
00 40 85 19 d4 93 ff ff 00 10 00 00 00 00 00 00 .@..............
00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 ................
backtrace:
seq_open+0x2a/0x80
full_proxy_open+0x167/0x1e0
do_dentry_open+0x1e1/0x3a0
path_openat+0x961/0xa20
do_filp_open+0xae/0x120
do_sys_openat2+0x216/0x2f0
do_sys_open+0x57/0x80
do_syscall_64+0x33/0x40
entry_SYSCALL_64_after_hwframe+0x44/0xa9
unreferenced object 0xffff93d419854000 (size 4096):
comm "cat", pid 2332
Oracle
Oracle Oracle Database Server Risk Matrix: Oracle LogMiner — CVE-2021-2332
vendor_oracle·2021-10-15·CVSS 6.7
CVE-2021-2332 [MEDIUM] Oracle Oracle Database Server Risk Matrix: Oracle LogMiner — CVE-2021-2332
Oracle Oracle Database Server Risk Matrix: Oracle LogMiner vulnerability
CVE: CVE-2021-2332
CVSS: 6.7
Protocol: Oracle Net
Remote exploit: No
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-10-20
Published