PT-2021-7213 · Oracle · Oracle Cloud Infrastructure+1

Published

2021-11-15

·

Updated

2022-06-28

·

CVE-2022-21503

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Oracle Cloud Infrastructure (affected versions not specified) Oracle Identity Cloud Service (affected versions not specified)
Description The issue concerns a vulnerability in Oracle's cloud infrastructure products, allowing a high-privileged attacker with network access to compromise the system and gain unauthorized access to sensitive data. The vulnerability is related to insufficient protection of service data in Oracle Identity Cloud Service, which can be exploited by a remote attacker to access protected information.
Recommendations For Oracle Cloud Infrastructure, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Oracle Identity Cloud Service, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-03802
CVE-2022-21503

Affected Products

Oracle Cloud Infrastructure
Oracle Identity Cloud Service