PT-2021-6673 · Oracle · Oracle Enterprise Session Border Controller

Harold Siyu Zang

+1

·

Published

2021-11-15

·

Updated

2022-01-25

·

CVE-2022-21383

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Oracle Enterprise Session Border Controller versions 8.4 through 9.0
Description The issue is related to errors in resource release in the Log component of the Oracle Enterprise Session Border Controller. It allows a remote attacker to cause a partial denial of service using the HTTP protocol. The vulnerability can be easily exploited by a low-privileged attacker with network access via HTTP, resulting in unauthorized ability to cause a partial denial of service of the Oracle Enterprise Session Border Controller.
Recommendations For versions 8.4 and 9.0, consider restricting access to the Log component until a patch is available. As a temporary workaround, consider disabling the Log component to minimize the risk of exploitation. Restrict network access via HTTP to reduce the risk of unauthorized attacks.

Fix

Improper Resource Release

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02012
CVE-2022-21383

Affected Products

Oracle Enterprise Session Border Controller