Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Metrics
No CVSS v4.0
Attack Vector Network
Attack Complexity High
Privileges Required None
Scope Changed
Confidentiality Impact High
Integrity Impact High
Availability Impact High
User Interaction Required
No CVSS v3.0
Access Vector Network
Access Complexity High
Authentication None
Confidentiality Impact Partial
Integrity Impact Partial
Availability Impact Partial
This CVE is not in the KEV list.
The EPSS score is 0.02948.
Key SSVC decision points have not yet been added.
Affected Vendors & Products
| Vendors | Products |
|---|---|
|
Oracle
Subscribe
|
Advanced Networking Option
Subscribe
Agile Engineering Data Management
Subscribe
Agile Plm
Subscribe
Agile Product Lifecycle Management For Process
Subscribe
Airlines Data Model
Subscribe
Application Performance Management
Subscribe
Application Testing Suite
Subscribe
Argus Analytics
Subscribe
Argus Insight
Subscribe
Argus Mart
Subscribe
Argus Safety
Subscribe
Banking Apis
Subscribe
Banking Digital Experience
Subscribe
Banking Enterprise Default Management
Subscribe
Banking Platform
Subscribe
Big Data Spatial And Graph
Subscribe
Blockchain Platform
Subscribe
Clinical
Subscribe
Commerce Platform
Subscribe
Communications Application Session Controller
Subscribe
Communications Billing And Revenue Management
Subscribe
Communications Calendar Server
Subscribe
Communications Contacts Server
Subscribe
Communications Convergent Charging Controller
Subscribe
Communications Data Model
Subscribe
Communications Design Studio
Subscribe
Communications Diameter Intelligence Hub
Subscribe
Communications Ip Service Activator
Subscribe
Communications Metasolv Solution
Subscribe
Communications Network Charging And Control
Subscribe
Communications Network Integrity
Subscribe
Communications Pricing Design Center
Subscribe
Communications Services Gatekeeper
Subscribe
Communications Session Report Manager
Subscribe
Communications Session Route Manager
Subscribe
Data Integrator
Subscribe
Demantra Demand Management
Subscribe
Documaker
Subscribe
Enterprise Data Quality
Subscribe
Enterprise Manager Base Platform
Subscribe
Enterprise Manager Ops Center
Subscribe
Financial Services Analytical Applications Infrastructure
Subscribe
Financial Services Behavior Detection Platform
Subscribe
Financial Services Enterprise Case Management
Subscribe
Financial Services Foreign Account Tax Compliance Act Management
Subscribe
Financial Services Model Management And Governance
Subscribe
Financial Services Trade-based Anti Money Laundering
Subscribe
Flexcube Investor Servicing
Subscribe
Flexcube Private Banking
Subscribe
Fusion Middleware
Subscribe
Goldengate
Subscribe
Goldengate Application Adapters
Subscribe
Graph Server And Client
Subscribe
Health Sciences Clinical Development Analytics
Subscribe
Health Sciences Inform Crf Submit
Subscribe
Health Sciences Information Manager
Subscribe
Healthcare Data Repository
Subscribe
Healthcare Foundation
Subscribe
Healthcare Translational Research
Subscribe
Hospitality Inventory Management
Subscribe
Hospitality Opera 5
Subscribe
Hospitality Reporting And Analytics
Subscribe
Hospitality Suite8
Subscribe
Hyperion Infrastructure Technology
Subscribe
Ilearning
Subscribe
Instantis Enterprisetrack
Subscribe
Insurance Data Gateway
Subscribe
Insurance Insbridge Rating And Underwriting
Subscribe
Insurance Policy Administration
Subscribe
Insurance Rules Palette
Subscribe
Jd Edwards Enterpriseone Tools
Subscribe
Oss Support Tools
Subscribe
Peoplesoft Enterprise Peopletools
Subscribe
Policy Automation
Subscribe
Primavera Analytics
Subscribe
Primavera Data Warehouse
Subscribe
Primavera Gateway
Subscribe
Primavera P6 Enterprise Project Portfolio Management
Subscribe
Primavera P6 Professional Project Management
Subscribe
Primavera Unifier
Subscribe
Product Lifecycle Analytics
Subscribe
Rapid Planning
Subscribe
Real User Experience Insight
Subscribe
Retail Analytics
Subscribe
Retail Assortment Planning
Subscribe
Retail Back Office
Subscribe
Retail Central Office
Subscribe
Retail Customer Insights
Subscribe
Retail Extract Transform And Load
Subscribe
Retail Financial Integration
Subscribe
Retail Integration Bus
Subscribe
Retail Merchandising System
Subscribe
Retail Order Broker
Subscribe
Retail Order Management System
Subscribe
Retail Point-of-service
Subscribe
Retail Predictive Application Server
Subscribe
Retail Price Management
Subscribe
Retail Returns Management
Subscribe
Retail Service Backbone
Subscribe
Retail Store Inventory Management
Subscribe
Retail Xstore Point Of Service
Subscribe
Siebel Ui Framework
Subscribe
Spatial Studio
Subscribe
Storagetek Acsls
Subscribe
Storagetek Tape Analytics
Subscribe
Thesaurus Management System
Subscribe
Timesten In-memory Database
Subscribe
Utilities Framework
Subscribe
Utilities Testing Accelerator
Subscribe
Weblogic Server
Subscribe
Zfs Storage Application Integration Engineering Software
Subscribe
|
Configuration 1 [-]
|
No data.
No data.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-16810 | Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: oracle
Published:
Updated: 2024-08-03T16:38:57.682Z
Reserved: 2020-12-09T00:00:00
Link: CVE-2021-2351
No data.
Status : Modified
Published: 2021-07-21T15:15:21.827
Modified: 2024-11-21T06:02:56.483
Link: CVE-2021-2351
No data.
OpenCVE Enrichment
No data.
EUVD