Lucene search

K
cveOracleCVE-2021-2351
HistoryJul 21, 2021 - 3:15 p.m.

CVE-2021-2351

2021-07-2115:15:21
CWE-384
CWE-327
oracle
web.nvd.nist.gov
165
9
cve-2021-2351
oracle
database server
vulnerability
advanced networking option
security
nvd
cve
network encryption

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.013

Percentile

86.0%

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: “Changes in Native Network Encryption with the July 2021 Critical Patch Update” (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

Affected configurations

Nvd
Vulners
Node
oracleadvanced_networking_optionMatch12.1.0.2
OR
oracleadvanced_networking_optionMatch12.2.0.1
OR
oracleadvanced_networking_optionMatch19c
OR
oracleagile_engineering_data_managementMatch6.2.1.0
OR
oracleagile_plmMatch9.3.6
OR
oracleagile_product_lifecycle_management_for_processMatch6.2.2.0
OR
oracleagile_product_lifecycle_management_for_processMatch6.2.3.0
OR
oracleairlines_data_modelMatch12.1.1.0.0
OR
oracleairlines_data_modelMatch12.2.0.1.0
OR
oracleapplication_performance_managementMatch13.4.1.0
OR
oracleapplication_performance_managementMatch13.5.1.0
OR
oracleapplication_testing_suiteMatch13.3.0.1
OR
oracleargus_analyticsMatch8.2.1
OR
oracleargus_analyticsMatch8.2.2
OR
oracleargus_analyticsMatch8.2.3
OR
oracleargus_insightMatch8.2.1
OR
oracleargus_insightMatch8.2.2
OR
oracleargus_insightMatch8.2.3
OR
oracleargus_martMatch8.2.1
OR
oracleargus_martMatch8.2.2
OR
oracleargus_martMatch8.2.3
OR
oracleargus_safetyMatch8.2.1
OR
oracleargus_safetyMatch8.2.2
OR
oracleargus_safetyMatch8.2.3
OR
oraclebanking_apisRange18.118.3
OR
oraclebanking_apisMatch19.1
OR
oraclebanking_apisMatch19.2
OR
oraclebanking_apisMatch20.1
OR
oraclebanking_apisMatch21.1
OR
oraclebanking_digital_experienceRange18.118.3
OR
oraclebanking_digital_experienceMatch17.2
OR
oraclebanking_digital_experienceMatch19.1
OR
oraclebanking_digital_experienceMatch19.2
OR
oraclebanking_digital_experienceMatch20.1
OR
oraclebanking_digital_experienceMatch21.1
OR
oraclebanking_enterprise_default_managementMatch2.10.0
OR
oraclebanking_enterprise_default_managementMatch2.12.0
OR
oraclebanking_platformMatch2.6.2
OR
oraclebanking_platformMatch2.7.1
OR
oraclebanking_platformMatch2.12.0
OR
oraclebig_data_spatial_and_graphRange<23.1
OR
oracleblockchain_platformMatch21.1.2
OR
oracleclinicalMatch5.2.1
OR
oracleclinicalMatch5.2.2
OR
oraclecommerce_platformMatch11.3.0
OR
oraclecommerce_platformMatch11.3.1
OR
oraclecommerce_platformMatch11.3.2
OR
oraclecommunications_application_session_controllerMatch3.9.0
OR
oraclecommunications_billing_and_revenue_managementMatch12.0.0.4
OR
oraclecommunications_billing_and_revenue_managementMatch12.0.0.5
OR
oraclecommunications_calendar_serverMatch8.0.0.5.0
OR
oraclecommunications_contacts_serverMatch8.0.0.3.0
OR
oraclecommunications_convergent_charging_controllerRange12.0.1.0.012.0.4.0.0
OR
oraclecommunications_convergent_charging_controllerMatch6.0.1.0.0
OR
oraclecommunications_data_modelMatch11.3.2.1.0
OR
oraclecommunications_data_modelMatch11.3.2.2.0
OR
oraclecommunications_data_modelMatch11.3.2.3.0
OR
oraclecommunications_data_modelMatch12.1.0.1.0
OR
oraclecommunications_data_modelMatch12.1.2.0.0
OR
oraclecommunications_design_studioMatch7.3.5
OR
oraclecommunications_design_studioMatch7.4.0
OR
oraclecommunications_design_studioMatch7.4.1
OR
oraclecommunications_design_studioMatch7.4.2
OR
oraclecommunications_diameter_intelligence_hubRange8.0.08.2.3
OR
oraclecommunications_ip_service_activatorMatch7.4.0
OR
oraclecommunications_metasolv_solutionMatch6.3.1
OR
oraclecommunications_network_charging_and_controlRange12.0.1.012.0.4.0.0
OR
oraclecommunications_network_charging_and_controlMatch6.0.1.0.0
OR
oraclecommunications_network_integrityMatch7.3.5
OR
oraclecommunications_network_integrityMatch7.3.6
OR
oraclecommunications_pricing_design_centerMatch12.0.0.4
OR
oraclecommunications_pricing_design_centerMatch12.0.0.5
OR
oraclecommunications_services_gatekeeperMatch7.0
OR
oraclecommunications_session_report_managerRange8.0.08.2.5.0
OR
oraclecommunications_session_route_managerRange8.2.08.2.5
OR
oracledata_integratorMatch12.2.1.3.0
OR
oracledata_integratorMatch12.2.1.4.0
OR
oracledemantra_demand_managementRange12.2.612.2.11
OR
oracledocumakerRange12.6.212.6.4
OR
oracledocumakerMatch12.6.0
OR
oracledocumakerMatch12.7.0
OR
oracleenterprise_data_qualityMatch12.2.1.3.0
OR
oracleenterprise_data_qualityMatch12.2.1.4.0
OR
oracleenterprise_manager_base_platformMatch13.4.0.0
OR
oracleenterprise_manager_base_platformMatch13.5.0.0
OR
oracleenterprise_manager_ops_centerMatch12.4.0.0
OR
oraclefinancial_services_analytical_applications_infrastructureRange8.0.78.1.1
OR
oraclefinancial_services_behavior_detection_platformMatch8.0.7
OR
oraclefinancial_services_behavior_detection_platformMatch8.0.8
OR
oraclefinancial_services_behavior_detection_platformMatch8.0.11
OR
oraclefinancial_services_enterprise_case_managementMatch8.0.7
OR
oraclefinancial_services_enterprise_case_managementMatch8.0.8
OR
oraclefinancial_services_enterprise_case_managementMatch8.0.11
OR
oraclefinancial_services_foreign_account_tax_compliance_act_managementMatch8.0.7
OR
oraclefinancial_services_foreign_account_tax_compliance_act_managementMatch8.0.8
OR
oraclefinancial_services_foreign_account_tax_compliance_act_managementMatch8.0.11
OR
oraclefinancial_services_model_management_and_governanceRange8.0.8.0.08.1.1.0.0
OR
oraclefinancial_services_trade-based_anti_money_launderingMatch8.0.7enterprise
OR
oraclefinancial_services_trade-based_anti_money_launderingMatch8.0.8enterprise
OR
oracleflexcube_investor_servicingMatch12.0.4
OR
oracleflexcube_investor_servicingMatch12.1.0
OR
oracleflexcube_investor_servicingMatch12.3.0
OR
oracleflexcube_investor_servicingMatch12.4.0
OR
oracleflexcube_investor_servicingMatch14.4.0
OR
oracleflexcube_investor_servicingMatch14.5.0
OR
oracleflexcube_private_bankingMatch12.0.0
OR
oracleflexcube_private_bankingMatch12.1.0
OR
oraclefusion_middlewareMatch12.2.1.3.0
OR
oraclefusion_middlewareMatch12.2.1.4.0
OR
oraclegoldengateRange<12.3.0.1.0
OR
oraclegoldengateRange19.1.0.0.121.5.0.0.220118
OR
oraclegoldengate_application_adaptersRange<23.1
OR
oraclegraph_server_and_clientRange<21.4.0
OR
oraclehealth_sciences_clinical_development_analyticsMatch4.0.1
OR
oraclehealth_sciences_inform_crf_submitMatch6.2.1
OR
oraclehealth_sciences_information_managerMatch3.0.2
OR
oraclehealth_sciences_information_managerMatch3.0.3
OR
oraclehealthcare_data_repositoryMatch7.0.2
OR
oraclehealthcare_data_repositoryMatch8.1.0
OR
oraclehealthcare_data_repositoryMatch8.1.1
OR
oraclehealthcare_foundationRange7.3.07.3.0.2
OR
oraclehealthcare_foundationRange8.0.08.0.2
OR
oraclehealthcare_foundationRange8.1.08.1.1
OR
oraclehealthcare_translational_researchMatch4.1.0
OR
oraclehospitality_inventory_managementRange<9.1.0
OR
oraclehospitality_inventory_managementMatch9.1.0
OR
oraclehospitality_opera_5Match5.6
OR
oraclehospitality_reporting_and_analyticsMatch9.1.0
OR
oraclehospitality_suite8Match8.10.2
OR
oraclehospitality_suite8Match8.11.0
OR
oraclehospitality_suite8Match8.12.0
OR
oraclehospitality_suite8Match8.13.0
OR
oraclehospitality_suite8Match8.14.0
OR
oraclehyperion_infrastructure_technologyMatch11.2.7.0
OR
oracleilearningMatch6.2
OR
oracleilearningMatch6.3
OR
oracleinstantis_enterprisetrackMatch17.1
OR
oracleinstantis_enterprisetrackMatch17.2
OR
oracleinstantis_enterprisetrackMatch17.3
OR
oracleinsurance_data_gatewayMatch11.0.2
OR
oracleinsurance_data_gatewayMatch11.1.0
OR
oracleinsurance_data_gatewayMatch11.2.7
OR
oracleinsurance_data_gatewayMatch11.3.0
OR
oracleinsurance_data_gatewayMatch11.3.1
OR
oracleinsurance_insbridge_rating_and_underwritingRange5.45.6.0
OR
oracleinsurance_insbridge_rating_and_underwritingMatch5.2.0
OR
oracleinsurance_policy_administrationMatch11.0.2
OR
oracleinsurance_policy_administrationMatch11.1.0
OR
oracleinsurance_policy_administrationMatch11.2.7
OR
oracleinsurance_policy_administrationMatch11.3.0
OR
oracleinsurance_policy_administrationMatch11.3.1
OR
oracleinsurance_rules_paletteMatch11.0.2
OR
oracleinsurance_rules_paletteMatch11.1.0
OR
oracleinsurance_rules_paletteMatch11.2.7
OR
oracleinsurance_rules_paletteMatch11.3.0
OR
oracleinsurance_rules_paletteMatch11.3.1
OR
oraclejd_edwards_enterpriseone_toolsMatch9.2.6.3
OR
oracleoss_support_toolsRange<2.12.42
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.57
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.58
OR
oraclepeoplesoft_enterprise_peopletoolsMatch8.59
OR
oraclepolicy_automationRange12.2.012.2.24
OR
oracleprimavera_analyticsMatch18.8.3.3
OR
oracleprimavera_analyticsMatch19.12.11.1
OR
oracleprimavera_analyticsMatch20.12.12.0
OR
oracleprimavera_data_warehouseMatch18.8.3.3
OR
oracleprimavera_data_warehouseMatch19.12.11.1
OR
oracleprimavera_data_warehouseMatch20.12.12.0
OR
oracleprimavera_gatewayRange17.12.017.12.11
OR
oracleprimavera_gatewayRange18.8.018.8.12
OR
oracleprimavera_gatewayRange19.12.019.12.11
OR
oracleprimavera_gatewayRange20.12.020.12.7
OR
oracleprimavera_p6_enterprise_project_portfolio_managementRange17.12.0.017.12.20
OR
oracleprimavera_p6_enterprise_project_portfolio_managementRange18.8.0.018.8.24
OR
oracleprimavera_p6_enterprise_project_portfolio_managementRange19.12.0.019.12.17.0
OR
oracleprimavera_p6_enterprise_project_portfolio_managementRange20.12.0.020.12.9.0
OR
oracleprimavera_p6_professional_project_managementRange17.1217.12.20.0
OR
oracleprimavera_p6_professional_project_managementRange18.818.8.24.0
OR
oracleprimavera_p6_professional_project_managementRange19.12.0.019.12.17.0
OR
oracleprimavera_p6_professional_project_managementRange20.12.0.020.12.9.0
OR
oracleprimavera_unifierRange17.717.12
OR
oracleprimavera_unifierMatch18.8
OR
oracleprimavera_unifierMatch19.12
OR
oracleprimavera_unifierMatch20.12
OR
oracleprimavera_unifierMatch21.12
OR
oracleproduct_lifecycle_analyticsMatch3.6.1
OR
oraclerapid_planningRange12.2.612.2.11
OR
oraclereal_user_experience_insightMatch13.4.1.0
OR
oraclereal_user_experience_insightMatch13.5.1.0
OR
oracleretail_analyticsRange16.0.016.0.2
OR
oracleretail_assortment_planningMatch16.0.3
OR
oracleretail_back_officeMatch14.1
OR
oracleretail_central_officeMatch14.1
OR
oracleretail_customer_insightsRange16.016.0.2
OR
oracleretail_extract_transform_and_loadMatch13.2.8
OR
oracleretail_financial_integrationMatch14.1.3.2
OR
oracleretail_financial_integrationMatch15.0.3.1
OR
oracleretail_financial_integrationMatch16.0.3.0
OR
oracleretail_financial_integrationMatch19.0.1
OR
oracleretail_integration_busMatch14.1.3.2
OR
oracleretail_integration_busMatch15.0.3.1
OR
oracleretail_integration_busMatch16.0.3
OR
oracleretail_integration_busMatch19.0.1
OR
oracleretail_merchandising_systemMatch19.0.1
OR
oracleretail_order_brokerMatch16.0
OR
oracleretail_order_brokerMatch18.0
OR
oracleretail_order_brokerMatch19.1
OR
oracleretail_order_management_systemMatch19.5
OR
oracleretail_point-of-serviceMatch14.1
OR
oracleretail_predictive_application_serverMatch14.1.3
OR
oracleretail_predictive_application_serverMatch15.0.3
OR
oracleretail_predictive_application_serverMatch16.0.3
OR
oracleretail_price_managementMatch14.1
OR
oracleretail_price_managementMatch15.0
OR
oracleretail_price_managementMatch16.0
OR
oracleretail_returns_managementMatch14.1
OR
oracleretail_service_backboneMatch14.1.3.2
OR
oracleretail_service_backboneMatch15.0.3.1
OR
oracleretail_service_backboneMatch16.0.3
OR
oracleretail_service_backboneMatch19.0.1
OR
oracleretail_store_inventory_managementMatch14.1
OR
oracleretail_store_inventory_managementMatch15.0
OR
oracleretail_store_inventory_managementMatch16.0
OR
oracleretail_xstore_point_of_serviceMatch17.0.4
OR
oracleretail_xstore_point_of_serviceMatch18.0.3
OR
oracleretail_xstore_point_of_serviceMatch19.0.2
OR
oracleretail_xstore_point_of_serviceMatch20.0.1
OR
oraclesiebel_ui_frameworkRange21.12
OR
oraclespatial_studioRange<21.2.1
OR
oraclestoragetek_acslsMatch8.5.1
OR
oraclestoragetek_tape_analyticsMatch2.4
OR
oraclethesaurus_management_systemMatch5.2.3
OR
oraclethesaurus_management_systemMatch5.3.0
OR
oraclethesaurus_management_systemMatch5.3.1
OR
oracletimesten_in-memory_databaseRange<21.1.1.1.0
OR
oracletimesten_in-memory_databaseMatch21.1.1.1.0
OR
oracleutilities_frameworkRange4.3.0.1.04.3.0.6.0
OR
oracleutilities_frameworkMatch4.2.0.3.0
OR
oracleutilities_frameworkMatch4.4.0.0.0
OR
oracleutilities_frameworkMatch4.4.0.2.0
OR
oracleutilities_frameworkMatch4.4.0.3.0
OR
oracleutilities_testing_acceleratorMatch6.0.0.1.1
OR
oracleutilities_testing_acceleratorMatch6.0.0.2.2
OR
oracleutilities_testing_acceleratorMatch6.0.0.3.1
OR
oracleweblogic_serverMatch12.2.1.3.0
OR
oracleweblogic_serverMatch12.2.1.4.0
OR
oracleweblogic_serverMatch14.1.1.0.0
OR
oraclezfs_storage_application_integration_engineering_softwareMatch1.3.3
VendorProductVersionCPE
oracleadvanced_networking_option12.1.0.2cpe:2.3:a:oracle:advanced_networking_option:12.1.0.2:*:*:*:*:*:*:*
oracleadvanced_networking_option12.2.0.1cpe:2.3:a:oracle:advanced_networking_option:12.2.0.1:*:*:*:*:*:*:*
oracleadvanced_networking_option19ccpe:2.3:a:oracle:advanced_networking_option:19c:*:*:*:*:*:*:*
oracleagile_engineering_data_management6.2.1.0cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:*
oracleagile_plm9.3.6cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:*
oracleagile_product_lifecycle_management_for_process6.2.2.0cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.2.0:*:*:*:*:*:*:*
oracleagile_product_lifecycle_management_for_process6.2.3.0cpe:2.3:a:oracle:agile_product_lifecycle_management_for_process:6.2.3.0:*:*:*:*:*:*:*
oracleairlines_data_model12.1.1.0.0cpe:2.3:a:oracle:airlines_data_model:12.1.1.0.0:*:*:*:*:*:*:*
oracleairlines_data_model12.2.0.1.0cpe:2.3:a:oracle:airlines_data_model:12.2.0.1.0:*:*:*:*:*:*:*
oracleapplication_performance_management13.4.1.0cpe:2.3:a:oracle:application_performance_management:13.4.1.0:*:*:*:*:*:*:*
Rows per page:
1-10 of 2361

CNA Affected

[
  {
    "product": "WebLogic Server",
    "vendor": "Oracle Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "12.2.1.3.0"
      },
      {
        "status": "affected",
        "version": "12.2.1.4.0"
      },
      {
        "status": "affected",
        "version": "14.1.1.0.0"
      }
    ]
  }
]

Social References

More

CVSS2

5.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:H/Au:N/C:P/I:P/A:P

CVSS3

8.3

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.013

Percentile

86.0%