CVE-2021-2447
published 2021-07-21CVE-2021-2447: Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily…
PriorityP354critical9.9CVSS 3.1
AVNACLPRLUINSCCHIHAH
EPSS
1.09%
61.7th percentile
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| openstack | keystone | >= 0 < 2:21.0.1-0ubuntu2.1 | 2:21.0.1-0ubuntu2.1 |
| oracle | secure_global_desktop | — | — |
| oracle_corporation | secure_global_desktop | — | — |
| vyperlang | vyper | >= 0 < 0.3.0 | 0.3.0 |
CVSS provenance
nvdv3.19.9CRITICALCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
osv7.4HIGH
vendor_oracle9.9CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Oracle
Oracle Oracle Virtualization Risk Matrix: Server — CVE-2021-2447
vendor_oracle·2021-07-15·CVSS 9.9
CVE-2021-2447 [CRITICAL] Oracle Oracle Virtualization Risk Matrix: Server — CVE-2021-2447
Oracle Oracle Virtualization Risk Matrix: Server vulnerability
CVE: CVE-2021-2447
CVSS: 9.9
Protocol: Multiple
Remote exploit: No
Affected versions: Network
Advisory: cpujul2021 (JUL 2021)
OSV
keystone vulnerabilities
osv·2025-12-11·CVSS 7.4
CVE-2025-65073 keystone vulnerabilities
keystone vulnerabilities
Kay discovered that OpenStack Keystone incorrectly handled the ec2tokens
and s3tokens APIs. A remote attacker could possibly use this issue to
obtain unauthorized access and escalate privileges. (CVE-2025-65073)
It was discovered that OpenStack Keystone only validated the first 72
bytes of an application secret. An attacker could possibly use this issue
to bypass password complexity. (CVE-2021-3563)
It was discovered that OpenStack Keystone had a time lag before a token
should be revoked by the security policy. A remote administrator could use
this issue to maintain access for longer than expected. (CVE-2022-2447)
GHSA
GHSA-2p3h-vm38-7wjp: Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server)
ghsa_unreviewed·2022-05-24
CVE-2021-2447 [CRITICAL] GHSA-2p3h-vm38-7wjp: Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server)
Vulnerability in the Oracle Secure Global Desktop product of Oracle Virtualization (component: Server). The supported version that is affected is 5.6. Easily exploitable vulnerability allows low privileged attacker with network access via multiple protocols to compromise Oracle Secure Global Desktop. While the vulnerability is in Oracle Secure Global Desktop, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Oracle Secure Global Desktop. CVSS 3.1 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).
GHSA
Memory corruption when returning a literal struct with a private call inside of it
ghsa·2021-10-12
CVE-2021-41121 [HIGH] CWE-119 Memory corruption when returning a literal struct with a private call inside of it
Memory corruption when returning a literal struct with a private call inside of it
### Impact
When performing a function call inside a literal struct, there is a memory corruption issue that occurs because of an incorrect pointer to the the top of the stack.
### Patches
0.3.0 / #2447
*
GHSA
missing clamps for decimal args in external functions
ghsa·2021-10-06
CVE-2021-41122 [MEDIUM] CWE-682 missing clamps for decimal args in external functions
missing clamps for decimal args in external functions
### Impact
The following code does not properly validate that its input is in bounds.
```python
@external
def foo(x: decimal) -> decimal:
return x
```
### Patches
0.3.0 / #2447
### Workarounds
Don't use decimal args
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-21
Published