CVE-2023-21994Corporation Mobile Security Suite vulnerability

4 documents4 sources
Severity
6.5MEDIUMNVD
EPSS
0.2%
top 63.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 18

Description

Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App). Supported versions that are affected are Prior to 11.1.2.3.1. Easily exploitable vulnerability allows unauthenticated attacker with access to the physical communication segment attached to the hardware where the Oracle Mobile Security Suite executes to compromise Oracle Mobile Security Suite. Successful attacks of this vulnerability can result in unauthorized acces

CVSS vector

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5oracle_corporation/mobile_security_suite*11.1.2.3.1
NVDoracle/fusion_middleware< 11.1.2.3.1

Patches

🔴Vulnerability Details

2
CVEList
CVE-2023-21994: Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App)2023-07-18
GHSA
GHSA-79mr-wphf-jwxg: Vulnerability in the Oracle Mobile Security Suite product of Oracle Fusion Middleware (component: Android Mobile Authenticator App)2023-07-18

📋Vendor Advisories

1
Oracle
Oracle Oracle Fusion Middleware Risk Matrix: Android Mobile Authenticator App — CVE-2023-219942023-07-15
CVE-2023-21994 — MEDIUM severity | cvebase