PT-2021-2869 · Oracle · Oracle Secure Global Desktop

Published

2021-04-20

·

Updated

2021-12-04

·

CVE-2021-2248

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Oracle Secure Global Desktop version 5.6
Description The issue is related to insufficient input validation in the Server component of Oracle Secure Global Desktop. This can be exploited by a remote attacker to gain full control over the application or execute arbitrary code using the SKID protocol. The vulnerability is easily exploitable and can be compromised by an unauthenticated attacker with network access via multiple protocols, potentially impacting additional products and resulting in the takeover of Oracle Secure Global Desktop.
Recommendations For Oracle Secure Global Desktop version 5.6, consider restricting network access to the Server component until a patch is available. As a temporary workaround, disabling the vulnerable Server component may help minimize the risk of exploitation. Avoid using the SKID protocol in the affected Oracle Secure Global Desktop version until the issue is resolved.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-02425
CVE-2021-2248

Affected Products

Oracle Secure Global Desktop