CVE-2023-21890

CWE-94Code Injection4 documents4 sources
Severity
9.8CRITICAL
EPSS
2.8%
top 13.87%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 18

Description

Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to compromise Oracle Communications Converged Application Server. Successful attacks of this vulnerability can result in takeover of Oracle Communications Converged Application Server. CVSS 3.1 Base Score 9.8 (Confidentiality

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Patches

🔴Vulnerability Details

2
GHSA
GHSA-r23h-h8pw-fc6p: Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core)2023-01-18
CVEList
CVE-2023-21890: Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core)2023-01-17

📋Vendor Advisories

1
Oracle
Oracle Oracle Communications Risk Matrix: Core — CVE-2023-218902023-01-15
CVE-2023-21890 (CRITICAL CVSS 9.8) | Vulnerability in the Oracle Communi | cvebase.io