CVE-2021-2351
published 2021-07-21CVE-2021-2351: Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c…
PriorityP347high7.5CVSS 3.1
AVNACHPRNUIRSUCHIHAH
EPSS
2.50%
82.9th percentile
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Affected
251 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| oracle | advanced_networking_option | — | — |
| oracle | advanced_networking_option | — | — |
| oracle | advanced_networking_option | — | — |
| oracle | agile_engineering_data_management | — | — |
| oracle | agile_plm | — | — |
| oracle | agile_product_lifecycle_management_for_process | — | — |
| oracle | agile_product_lifecycle_management_for_process | — | — |
| oracle | airlines_data_model | — | — |
| oracle | airlines_data_model | — | — |
| oracle | application_performance_management | — | — |
| oracle | application_performance_management | — | — |
| oracle | application_testing_suite | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_analytics | — | — |
| oracle | argus_insight | — | — |
| oracle | argus_insight | — | — |
| oracle | argus_insight | — | — |
| oracle | argus_mart | — | — |
| oracle | argus_mart | — | — |
| oracle | argus_mart | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | argus_safety | — | — |
| oracle | banking_apis | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.05.1MEDIUMAV:N/AC:H/Au:N/C:P/I:P/A:P
vendor_oracle8.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle iLearning Risk Matrix: Installation (JDBC) — CVE-2021-2351
vendor_oracle·2023-04-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle iLearning Risk Matrix: Installation (JDBC) — CVE-2021-2351
Oracle Oracle iLearning Risk Matrix: Installation (JDBC) vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Food and Beverage Applications Risk Matrix: Reporting — CVE-2021-2351
vendor_oracle·2023-01-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle Food and Beverage Applications Risk Matrix: Reporting — CVE-2021-2351
Oracle Oracle Food and Beverage Applications Risk Matrix: Reporting vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Security (OJDBC) — CVE-2021-2351
vendor_oracle·2022-10-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle Communications Risk Matrix: Security (OJDBC) — CVE-2021-2351
Oracle Oracle Communications Risk Matrix: Security (OJDBC) vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2022 (OCT 2022)
Oracle
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Oracle TimesTen In-Memory Database Cache — CVE-2021-2351
vendor_oracle·2022-07-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle TimesTen In-Memory Database Risk Matrix: Oracle TimesTen In-Memory Database Cache — CVE-2021-2351
Oracle Oracle TimesTen In-Memory Database Risk Matrix: Oracle TimesTen In-Memory Database Cache vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2022 (JUL 2022)
Oracle
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (JDBC, OCCI) — CVE-2021-2351
vendor_oracle·2022-04-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (JDBC, OCCI) — CVE-2021-2351
Oracle Oracle Blockchain Platform Risk Matrix: BCS Console (JDBC, OCCI) vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2022 (APR 2022)
Oracle
Oracle Oracle Airlines Data Model Risk Matrix: Installation (JDBC) — CVE-2021-2351
vendor_oracle·2022-01-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle Airlines Data Model Risk Matrix: Installation (JDBC) — CVE-2021-2351
Oracle Oracle Airlines Data Model Risk Matrix: Installation (JDBC) vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2022 (JAN 2022)
Oracle
Oracle Oracle Communications Applications Risk Matrix: Reports (JDBC) — CVE-2021-2351
vendor_oracle·2021-10-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle Communications Applications Risk Matrix: Reports (JDBC) — CVE-2021-2351
Oracle Oracle Communications Applications Risk Matrix: Reports (JDBC) vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2021 (OCT 2021)
Oracle
Oracle Oracle Database Server Risk Matrix: Advanced Networking Option — CVE-2021-2351
vendor_oracle·2021-07-15·CVSS 8.3
CVE-2021-2351 [HIGH] Oracle Oracle Database Server Risk Matrix: Advanced Networking Option — CVE-2021-2351
Oracle Oracle Database Server Risk Matrix: Advanced Networking Option vulnerability
CVE: CVE-2021-2351
CVSS: 8.3
Protocol: Oracle Net
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
GHSA
GHSA-gm3p-p24r-4wxq: Vulnerability in the Advanced Networking Option component of Oracle Database Server
ghsa_unreviewed·2022-05-24·CVSS 8.3
CVE-2021-2351 [HIGH] CWE-327 GHSA-gm3p-p24r-4wxq: Vulnerability in the Advanced Networking Option component of Oracle Database Server
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Cha
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://packetstormsecurity.com/files/165255/Oracle-Database-Protection-Mechanism-Bypass.htmlhttp://packetstormsecurity.com/files/165258/Oracle-Database-Weak-NNE-Integrity-Key-Derivation.htmlhttp://seclists.org/fulldisclosure/2021/Dec/19http://seclists.org/fulldisclosure/2021/Dec/20https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujan2023.htmlhttps://www.oracle.com/security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.htmlhttp://packetstormsecurity.com/files/165255/Oracle-Database-Protection-Mechanism-Bypass.htmlhttp://packetstormsecurity.com/files/165258/Oracle-Database-Weak-NNE-Integrity-Key-Derivation.htmlhttp://seclists.org/fulldisclosure/2021/Dec/19http://seclists.org/fulldisclosure/2021/Dec/20https://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://www.oracle.com/security-alerts/cpujan2023.htmlhttps://www.oracle.com/security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpujul2022.htmlhttps://www.oracle.com/security-alerts/cpuoct2021.html
2021-07-21
Published