PT-2021-7213 · Oracle · Oracle Cloud Infrastructure+1
Published
2021-11-15
·
Updated
2022-06-28
·
CVE-2022-21503
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:L/Au:S/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Oracle Cloud Infrastructure (affected versions not specified)
Oracle Identity Cloud Service (affected versions not specified)
Description
The issue concerns a vulnerability in Oracle's cloud infrastructure products, allowing a high-privileged attacker with network access to compromise the system and gain unauthorized access to sensitive data. The vulnerability is related to insufficient protection of service data in Oracle Identity Cloud Service, which can be exploited by a remote attacker to access protected information.
Recommendations
For Oracle Cloud Infrastructure, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
For Oracle Identity Cloud Service, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Oracle Cloud Infrastructure
Oracle Identity Cloud Service