PT-2021-21003 · Oracle · Oracle Database Server
Published
2021-10-20
·
Updated
2021-10-26
·
CVE-2021-35599
CVSS v3.1
8.2
High
| Vector | AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Oracle Database Server version 21c
Description:
The issue affects the Zero Downtime DB Migration to Cloud component, allowing a high-privileged attacker with local logon privilege to compromise it. Successful attacks can result in the takeover of the Zero Downtime DB Migration to Cloud, potentially impacting additional products.
Recommendations:
For Oracle Database Server version 21c, update to a version that includes the fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the Zero Downtime DB Migration to Cloud component to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database Server