CVE-2023-21994 — Corporation Mobile Security Suite vulnerability
4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 63.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 18
Description
Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App). Supported versions that are affected are Prior to 11.1.2.3.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Security Suite executes to compromise Oracle Mobile Security Suite. Successful attacks of this vulnerability can result in unauthorized acces…
CVSS vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6
Affected Packages2 packages
Patches
🔴Vulnerability Details
2CVEList▶
CVE-2023-21994: Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App)↗2023-07-18
GHSA▶
GHSA-79mr-wphf-jwxg: Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App)↗2023-07-18
📋Vendor Advisories
1Oracle▶
Oracle Oracle Fusion Middleware Risk Matrix: Android Mobile Authenticator App — CVE-2023-21994↗2023-07-15