HIGH · 8.3

CVE-2021-2351

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unau...

Vulnerability Description

Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

CVSS Score

8.3

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
OracleAdvanced Networking Option12.1.0.2
OracleAgile Engineering Data Management6.2.1.0
OracleAgile Plm9.3.6
OracleAgile Product Lifecycle Management For Process6.2.2.0
OracleAirlines Data Model12.1.1.0.0
OracleApplication Performance Management13.4.1.0
OracleApplication Testing Suite13.3.0.1
OracleArgus Analytics8.2.1
OracleArgus Insight8.2.1
OracleArgus Mart8.2.1
OracleArgus Safety8.2.1
OracleBanking Apis>= 18.1, <= 18.3
OracleBanking Digital Experience>= 18.1, <= 18.3
OracleBanking Enterprise Default Management2.10.0
OracleBanking Platform2.6.2
OracleBig Data Spatial And Graph< 23.1
OracleBlockchain Platform21.1.2
OracleClinical5.2.1
OracleCommerce Platform11.3.0
OracleCommunications Application Session Controller3.9.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-2351?

CVE-2021-2351 is a vulnerability with a CVSS score of 8.3 (HIGH). Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unau...

How severe is CVE-2021-2351?

CVE-2021-2351 has been rated HIGH with a CVSS base score of 8.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-2351?

Check the references section above for vendor advisories and patch information. Affected products include: Oracle Advanced Networking Option, Oracle Agile Engineering Data Management, Oracle Agile Plm, Oracle Agile Product Lifecycle Management For Process, Oracle Airlines Data Model.