PT-2021-16125 · Oracle · Oracle Communications Interactive Session Recorder

Kosong

·

Published

2021-10-20

·

Updated

2021-10-26

·

CVE-2021-2461

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions Oracle Communications Interactive Session Recorder version 6.4
Description The issue allows an unauthenticated attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder. Successful attacks can result in unauthorized update, insert, or delete access to some accessible data, as well as unauthorized read access to a subset of accessible data and the ability to cause a partial denial of service of Oracle Communications Interactive Session Recorder. Attacks may significantly impact additional products.
Recommendations For version 6.4, update to a version that includes the fix for this issue to prevent unauthorized access and potential denial of service. As a temporary workaround, consider restricting network access via HTTP to the Provision API component until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-2461

Affected Products

Oracle Communications Interactive Session Recorder