Oracle · Oracle Communications Interactive Session Recorder · CVE-2021-2461
**Name of the Vulnerable Software and Affected Versions**
Oracle Communications Interactive Session Recorder version 6.4
**Description**
The issue allows an unauthenticated attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data and the ability to cause a partial denial of service of Oracle Communications Interactive Session Recorder. Attacks may significantly impact additional products.
**Recommendations**
For version 6.4, update to a version that includes the fix for this issue to prevent unauthorized access and potential denial of service. As a temporary workaround, consider restricting network access via HTTP to the Provision API component until a patch is available.