CVE-2022-21405
published 2022-04-19CVE-2022-21405: Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer). The supported version that is affected is 18.3. Easily…
PriorityP420medium5.5CVSS 3.1
AVLACLPRHUIRSCCHINAN
EPSS
0.27%
19.1th percentile
Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer). The supported version that is affected is 18.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where OSS Support Tools executes to compromise OSS Support Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N).
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| msrc | microsoft_visual_studio_2022_version_17.12 | — | — |
| oracle | oss_support_tools | — | — |
| oracle_corporation | oss_support_tools | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N
nvdv2.01.2LOWAV:L/AC:H/Au:N/C:P/I:N/A:N
vendor_msrc7.3HIGH
vendor_oracle5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Visual Studio Elevation of Privilege Vulnerability
vendor_msrc·2025-01-14·CVSS 7.3
CVE-2025-21405 [HIGH] CWE-284 Visual Studio Elevation of Privilege Vulnerability
Visual Studio Elevation of Privilege Vulnerability
Visual Studio: Visual Studio
Microsoft: Microsoft
Customer Action Required: Yes
Impact: Elevation of Privilege
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely
Remediation: Release Notes
Reference: https://my.visualstudio.com/Downloads?q=Visual Studio 2022 version 17.12
Reference: https://learn.microsoft.com/en-us/visualstudio/releases/2022/release-notes
Oracle
Oracle Oracle Support Tools Risk Matrix: Oracle Explorer — CVE-2022-21405
vendor_oracle·2022-04-15·CVSS 5.5
CVE-2022-21405 [MEDIUM] Oracle Oracle Support Tools Risk Matrix: Oracle Explorer — CVE-2022-21405
Oracle Oracle Support Tools Risk Matrix: Oracle Explorer vulnerability
CVE: CVE-2022-21405
CVSS: 5.5
Protocol: None
Remote exploit: No
Affected versions: Local
Advisory: cpuapr2022 (APR 2022)
GHSA
GHSA-2w56-jm3g-7vcg: Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer)
ghsa_unreviewed·2022-04-20
CVE-2022-21405 [MEDIUM] GHSA-2w56-jm3g-7vcg: Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer)
Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Oracle Explorer). The supported version that is affected is 18.3. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where OSS Support Tools executes to compromise OSS Support Tools. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in OSS Support Tools, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all OSS Support Tools accessible data. CVSS 3.1 Base Score 5.5 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-04-19
Published