Lucene search

K
cveOracleCVE-2021-2257
HistoryApr 22, 2021 - 10:15 p.m.

CVE-2021-2257

2021-04-2222:15:15
oracle
web.nvd.nist.gov
27
4
cve-2021-2257
oracle
storage cloud
software appliance
vulnerability
network access
confidentiality impacts
nvd

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

22.7%

Vulnerability in the Oracle Storage Cloud Software Appliance product of Oracle Storage Gateway (component: Management Console). The supported version that is affected is Prior to 16.3.1.4.2. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Storage Cloud Software Appliance. While the vulnerability is in Oracle Storage Cloud Software Appliance, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle Storage Cloud Software Appliance accessible data. Note: Updating the Oracle Storage Cloud Software Appliance to version 16.3.1.4.2 or later will address these vulnerabilities. Download the latest version of Oracle Storage Cloud Software Appliance from <a href=“https://www.oracle.com/downloads/cloud/oscsa-downloads.html”>here. Refer to Document <a href=“https://support.oracle.com/rstype=doc&id=2768897.1”>2768897.1 for more details. CVSS 3.1 Base Score 4.1 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N).

Affected configurations

Nvd
Vulners
Node
oraclestorage_cloud_software_applianceRange<16.3.1.4.2
VendorProductVersionCPE
oraclestorage_cloud_software_appliance*cpe:2.3:a:oracle:storage_cloud_software_appliance:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Cloud Infrastructure",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "lessThan": "16.3.1.4.2",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      }
    ]
  }
]

Social References

More

CVSS2

4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:N/A:N

CVSS3

4.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N

AI Score

4.1

Confidence

High

EPSS

0.001

Percentile

22.7%

Related for CVE-2021-2257