PT-2021-16125 · Oracle · Oracle Communications Interactive Session Recorder
Kosong
·
Published
2021-10-20
·
Updated
2021-10-26
·
CVE-2021-2461
CVSS v3.1
8.3
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Oracle Communications Interactive Session Recorder version 6.4
Description
The issue allows an unauthenticated attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data and the ability to cause a partial denial of service of Oracle Communications Interactive Session Recorder. Attacks may significantly impact additional products.
Recommendations
For version 6.4, update to a version that includes the fix for this issue to prevent unauthorized access and potential denial of service. As a temporary workaround, consider restricting network access via HTTP to the Provision API component until a patch is available.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Communications Interactive Session Recorder