Lucene search

K
cvelistOracleCVELIST:CVE-2021-2175
HistoryApr 22, 2021 - 12:00 a.m.

CVE-2021-2175

2021-04-2200:00:00
oracle
www.cve.org
2

2.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

3.1 Low

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any View, Select Any View privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Database Vault accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).

CNA Affected

[
  {
    "vendor": "Oracle Corporation",
    "product": "Database - Enterprise Edition",
    "versions": [
      {
        "version": "12.1.0.2",
        "status": "affected"
      },
      {
        "version": "12.2.0.1",
        "status": "affected"
      },
      {
        "version": "18c",
        "status": "affected"
      },
      {
        "version": "19c",
        "status": "affected"
      }
    ]
  }
]

2.7 Low

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

HIGH

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N

3.1 Low

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

74.9%

Related for CVELIST:CVE-2021-2175