PT-2021-5455 · Oracle · Oracle Database Server
Published
2021-03-02
·
Updated
2024-11-17
·
CVE-2021-2351
CVSS v3.1
8.3
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Oracle Database Server versions 12.1.0.2, 12.2.0.1 and 19c
Description
The issue is related to the Advanced Networking Option component of Oracle Database Server, allowing an unauthenticated attacker with network access via Oracle Net to compromise this component. Successful attacks require human interaction from a person other than the attacker and may significantly impact additional products, potentially resulting in the takeover of Advanced Networking Option. The vulnerability is difficult to exploit.
Recommendations
For versions 12.1.0.2, 12.2.0.1, and 19c, review the "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1) and apply the necessary changes to prevent the use of weaker ciphers.
As a temporary workaround, consider restricting access to the Advanced Networking Option component until the issue is resolved.
Apply the updates introduced in the July 2021 Critical Patch Update to deal with the vulnerability and prevent the use of weaker ciphers.
Exploit
Fix
Improper Authentication
Use of a Broken Cryptographic Algorithm
Session Fixation
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Oracle Database Server