CVE-2021-2351
21.07.2021, 15:15
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).Enginsight
Vendor | Product | Version |
---|---|---|
oracle | advanced_networking_option | 12.1.0.2 |
oracle | advanced_networking_option | 12.2.0.1 |
oracle | agile_engineering_data_management | 6.2.1.0 |
oracle | agile_plm | 9.3.6 |
oracle | agile_product_lifecycle_management_for_process | 6.2.2.0 |
oracle | agile_product_lifecycle_management_for_process | 6.2.3.0 |
oracle | airlines_data_model | 12.1.1.0.0 |
oracle | airlines_data_model | 12.2.0.1.0 |
oracle | application_performance_management | 13.4.1.0 |
oracle | application_performance_management | 13.5.1.0 |
oracle | application_testing_suite | 13.3.0.1 |
oracle | argus_analytics | 8.2.1 |
oracle | argus_analytics | 8.2.2 |
oracle | argus_analytics | 8.2.3 |
oracle | argus_insight | 8.2.1 |
oracle | argus_insight | 8.2.2 |
oracle | argus_insight | 8.2.3 |
oracle | argus_mart | 8.2.1 |
oracle | argus_mart | 8.2.2 |
oracle | argus_mart | 8.2.3 |
oracle | argus_safety | 8.2.1 |
oracle | argus_safety | 8.2.2 |
oracle | argus_safety | 8.2.3 |
oracle | banking_apis | 18.1 ≤ 𝑥 ≤ 18.3 |
oracle | banking_apis | 19.1 |
oracle | banking_apis | 19.2 |
oracle | banking_apis | 20.1 |
oracle | banking_apis | 21.1 |
oracle | banking_digital_experience | 18.1 ≤ 𝑥 ≤ 18.3 |
oracle | banking_digital_experience | 17.2 |
oracle | banking_digital_experience | 19.1 |
oracle | banking_digital_experience | 19.2 |
oracle | banking_digital_experience | 20.1 |
oracle | banking_digital_experience | 21.1 |
oracle | banking_enterprise_default_management | 2.10.0 |
oracle | banking_enterprise_default_management | 2.12.0 |
oracle | banking_platform | 2.6.2 |
oracle | banking_platform | 2.7.1 |
oracle | banking_platform | 2.12.0 |
oracle | big_data_spatial_and_graph | 𝑥 < 23.1 |
oracle | blockchain_platform | 21.1.2 |
oracle | clinical | 5.2.1 |
oracle | clinical | 5.2.2 |
oracle | commerce_platform | 11.3.0 |
oracle | commerce_platform | 11.3.1 |
oracle | commerce_platform | 11.3.2 |
oracle | communications_application_session_controller | 3.9.0 |
oracle | communications_billing_and_revenue_management | 12.0.0.4 |
oracle | communications_billing_and_revenue_management | 12.0.0.5 |
oracle | communications_calendar_server | 8.0.0.5.0 |
oracle | communications_contacts_server | 8.0.0.3.0 |
oracle | communications_convergent_charging_controller | 12.0.1.0.0 ≤ 𝑥 ≤ 12.0.4.0.0 |
oracle | communications_convergent_charging_controller | 6.0.1.0.0 |
oracle | communications_data_model | 11.3.2.1.0 |
oracle | communications_data_model | 11.3.2.2.0 |
oracle | communications_data_model | 11.3.2.3.0 |
oracle | communications_data_model | 12.1.0.1.0 |
oracle | communications_data_model | 12.1.2.0.0 |
oracle | communications_design_studio | 7.3.5 |
oracle | communications_design_studio | 7.4.0 |
oracle | communications_design_studio | 7.4.1 |
oracle | communications_design_studio | 7.4.2 |
oracle | communications_diameter_intelligence_hub | 8.0.0 ≤ 𝑥 ≤ 8.2.3 |
oracle | communications_ip_service_activator | 7.4.0 |
oracle | communications_metasolv_solution | 6.3.1 |
oracle | communications_network_charging_and_control | 12.0.1.0 ≤ 𝑥 ≤ 12.0.4.0.0 |
oracle | communications_network_charging_and_control | 6.0.1.0.0 |
oracle | communications_network_integrity | 7.3.5 |
oracle | communications_network_integrity | 7.3.6 |
oracle | communications_pricing_design_center | 12.0.0.4 |
oracle | communications_pricing_design_center | 12.0.0.5 |
oracle | communications_services_gatekeeper | 7.0 |
oracle | communications_session_report_manager | 8.0.0 ≤ 𝑥 ≤ 8.2.5.0 |
oracle | communications_session_route_manager | 8.2.0 ≤ 𝑥 ≤ 8.2.5 |
oracle | data_integrator | 12.2.1.3.0 |
oracle | data_integrator | 12.2.1.4.0 |
oracle | demantra_demand_management | 12.2.6 ≤ 𝑥 ≤ 12.2.11 |
oracle | documaker | 12.6.2 ≤ 𝑥 ≤ 12.6.4 |
oracle | documaker | 12.6.0 |
oracle | documaker | 12.7.0 |
oracle | enterprise_data_quality | 12.2.1.3.0 |
oracle | enterprise_data_quality | 12.2.1.4.0 |
oracle | enterprise_manager_base_platform | 13.4.0.0 |
oracle | enterprise_manager_base_platform | 13.5.0.0 |
oracle | enterprise_manager_ops_center | 12.4.0.0 |
oracle | financial_services_analytical_applications_infrastructure | 8.0.7 ≤ 𝑥 ≤ 8.1.1 |
oracle | financial_services_behavior_detection_platform | 8.0.7 |
oracle | financial_services_behavior_detection_platform | 8.0.8 |
oracle | financial_services_behavior_detection_platform | 8.0.11 |
oracle | financial_services_enterprise_case_management | 8.0.7 |
oracle | financial_services_enterprise_case_management | 8.0.8 |
oracle | financial_services_enterprise_case_management | 8.0.11 |
oracle | financial_services_foreign_account_tax_compliance_act_management | 8.0.7 |
oracle | financial_services_foreign_account_tax_compliance_act_management | 8.0.8 |
oracle | financial_services_foreign_account_tax_compliance_act_management | 8.0.11 |
oracle | financial_services_model_management_and_governance | 8.0.8.0.0 ≤ 𝑥 ≤ 8.1.1.0.0 |
oracle | financial_services_trade-based_anti_money_laundering | 8.0.7 |
oracle | financial_services_trade-based_anti_money_laundering | 8.0.8 |
oracle | flexcube_investor_servicing | 12.0.4 |
oracle | flexcube_investor_servicing | 12.1.0 |
oracle | flexcube_investor_servicing | 12.3.0 |
oracle | flexcube_investor_servicing | 12.4.0 |
oracle | flexcube_investor_servicing | 14.4.0 |
oracle | flexcube_investor_servicing | 14.5.0 |
oracle | flexcube_private_banking | 12.0.0 |
oracle | flexcube_private_banking | 12.1.0 |
oracle | fusion_middleware | 12.2.1.3.0 |
oracle | fusion_middleware | 12.2.1.4.0 |
oracle | goldengate | 𝑥 < 12.3.0.1.0 |
oracle | goldengate | 19.1.0.0.1 ≤ 𝑥 < 21.5.0.0.220118 |
oracle | goldengate_application_adapters | 𝑥 < 23.1 |
oracle | graph_server_and_client | 𝑥 < 21.4.0 |
oracle | health_sciences_clinical_development_analytics | 4.0.1 |
oracle | health_sciences_inform_crf_submit | 6.2.1 |
oracle | health_sciences_information_manager | 3.0.2 |
oracle | health_sciences_information_manager | 3.0.3 |
oracle | healthcare_data_repository | 7.0.2 |
oracle | healthcare_data_repository | 8.1.0 |
oracle | healthcare_data_repository | 8.1.1 |
oracle | healthcare_foundation | 7.3.0 ≤ 𝑥 ≤ 7.3.0.2 |
oracle | healthcare_foundation | 8.0.0 ≤ 𝑥 ≤ 8.0.2 |
oracle | healthcare_foundation | 8.1.0 ≤ 𝑥 ≤ 8.1.1 |
oracle | healthcare_translational_research | 4.1.0 |
oracle | hospitality_inventory_management | 𝑥 < 9.1.0 |
oracle | hospitality_inventory_management | 9.1.0 |
oracle | hospitality_opera_5 | 5.6 |
oracle | hospitality_reporting_and_analytics | 9.1.0 |
oracle | hospitality_suite8 | 8.10.2 |
oracle | hospitality_suite8 | 8.11.0 |
oracle | hospitality_suite8 | 8.12.0 |
oracle | hospitality_suite8 | 8.13.0 |
oracle | hospitality_suite8 | 8.14.0 |
oracle | hyperion_infrastructure_technology | 11.2.7.0 |
oracle | ilearning | 6.2 |
oracle | ilearning | 6.3 |
oracle | instantis_enterprisetrack | 17.1 |
oracle | instantis_enterprisetrack | 17.2 |
oracle | instantis_enterprisetrack | 17.3 |
oracle | insurance_data_gateway | 11.0.2 |
oracle | insurance_data_gateway | 11.1.0 |
oracle | insurance_data_gateway | 11.2.7 |
oracle | insurance_data_gateway | 11.3.0 |
oracle | insurance_data_gateway | 11.3.1 |
oracle | insurance_insbridge_rating_and_underwriting | 5.4 ≤ 𝑥 ≤ 5.6.0 |
oracle | insurance_insbridge_rating_and_underwriting | 5.2.0 |
oracle | insurance_policy_administration | 11.0.2 |
oracle | insurance_policy_administration | 11.1.0 |
oracle | insurance_policy_administration | 11.2.7 |
oracle | insurance_policy_administration | 11.3.0 |
oracle | insurance_policy_administration | 11.3.1 |
oracle | insurance_rules_palette | 11.0.2 |
oracle | insurance_rules_palette | 11.1.0 |
oracle | insurance_rules_palette | 11.2.7 |
oracle | insurance_rules_palette | 11.3.0 |
oracle | insurance_rules_palette | 11.3.1 |
oracle | jd_edwards_enterpriseone_tools | 9.2.6.3 |
oracle | oss_support_tools | 𝑥 < 2.12.42 |
oracle | peoplesoft_enterprise_peopletools | 8.57 |
oracle | peoplesoft_enterprise_peopletools | 8.58 |
oracle | peoplesoft_enterprise_peopletools | 8.59 |
oracle | policy_automation | 12.2.0 ≤ 𝑥 ≤ 12.2.24 |
oracle | primavera_analytics | 18.8.3.3 |
oracle | primavera_analytics | 19.12.11.1 |
oracle | primavera_analytics | 20.12.12.0 |
oracle | primavera_data_warehouse | 18.8.3.3 |
oracle | primavera_data_warehouse | 19.12.11.1 |
oracle | primavera_data_warehouse | 20.12.12.0 |
oracle | primavera_gateway | 17.12.0 ≤ 𝑥 ≤ 17.12.11 |
oracle | primavera_gateway | 18.8.0 ≤ 𝑥 ≤ 18.8.12 |
oracle | primavera_gateway | 19.12.0 ≤ 𝑥 ≤ 19.12.11 |
oracle | primavera_gateway | 20.12.0 ≤ 𝑥 ≤ 20.12.7 |
oracle | primavera_p6_enterprise_project_portfolio_management | 17.12.0.0 ≤ 𝑥 ≤ 17.12.20 |
oracle | primavera_p6_enterprise_project_portfolio_management | 18.8.0.0 ≤ 𝑥 ≤ 18.8.24 |
oracle | primavera_p6_enterprise_project_portfolio_management | 19.12.0.0 ≤ 𝑥 ≤ 19.12.17.0 |
oracle | primavera_p6_enterprise_project_portfolio_management | 20.12.0.0 ≤ 𝑥 ≤ 20.12.9.0 |
oracle | primavera_p6_professional_project_management | 17.12 ≤ 𝑥 ≤ 17.12.20.0 |
oracle | primavera_p6_professional_project_management | 18.8 ≤ 𝑥 ≤ 18.8.24.0 |
oracle | primavera_p6_professional_project_management | 19.12.0.0 ≤ 𝑥 ≤ 19.12.17.0 |
oracle | primavera_p6_professional_project_management | 20.12.0.0 ≤ 𝑥 ≤ 20.12.9.0 |
oracle | primavera_unifier | 17.7 ≤ 𝑥 ≤ 17.12 |
oracle | primavera_unifier | 18.8 |
oracle | primavera_unifier | 19.12 |
oracle | primavera_unifier | 20.12 |
oracle | primavera_unifier | 21.12 |
oracle | product_lifecycle_analytics | 3.6.1 |
oracle | rapid_planning | 12.2.6 ≤ 𝑥 ≤ 12.2.11 |
oracle | real_user_experience_insight | 13.4.1.0 |
oracle | real_user_experience_insight | 13.5.1.0 |
oracle | retail_analytics | 16.0.0 ≤ 𝑥 ≤ 16.0.2 |
oracle | retail_assortment_planning | 16.0.3 |
oracle | retail_back_office | 14.1 |
oracle | retail_central_office | 14.1 |
oracle | retail_customer_insights | 16.0 ≤ 𝑥 ≤ 16.0.2 |
oracle | retail_extract_transform_and_load | 13.2.8 |
oracle | retail_financial_integration | 14.1.3.2 |
oracle | retail_financial_integration | 15.0.3.1 |
oracle | retail_financial_integration | 16.0.3.0 |
oracle | retail_financial_integration | 19.0.1 |
oracle | retail_integration_bus | 14.1.3.2 |
oracle | retail_integration_bus | 15.0.3.1 |
oracle | retail_integration_bus | 16.0.3 |
oracle | retail_integration_bus | 19.0.1 |
oracle | retail_merchandising_system | 19.0.1 |
oracle | retail_order_broker | 16.0 |
oracle | retail_order_broker | 18.0 |
oracle | retail_order_broker | 19.1 |
oracle | retail_order_management_system | 19.5 |
oracle | retail_point-of-service | 14.1 |
oracle | retail_predictive_application_server | 14.1.3 |
oracle | retail_predictive_application_server | 15.0.3 |
oracle | retail_predictive_application_server | 16.0.3 |
oracle | retail_price_management | 14.1 |
oracle | retail_price_management | 15.0 |
oracle | retail_price_management | 16.0 |
oracle | retail_returns_management | 14.1 |
oracle | retail_service_backbone | 14.1.3.2 |
oracle | retail_service_backbone | 15.0.3.1 |
oracle | retail_service_backbone | 16.0.3 |
oracle | retail_service_backbone | 19.0.1 |
oracle | retail_store_inventory_management | 14.1 |
oracle | retail_store_inventory_management | 15.0 |
oracle | retail_store_inventory_management | 16.0 |
oracle | retail_xstore_point_of_service | 17.0.4 |
oracle | retail_xstore_point_of_service | 18.0.3 |
oracle | retail_xstore_point_of_service | 19.0.2 |
oracle | retail_xstore_point_of_service | 20.0.1 |
oracle | siebel_ui_framework | 𝑥 ≤ 21.12 |
oracle | spatial_studio | 𝑥 < 21.2.1 |
oracle | storagetek_acsls | 8.5.1 |
oracle | storagetek_tape_analytics | 2.4 |
oracle | thesaurus_management_system | 5.2.3 |
oracle | thesaurus_management_system | 5.3.0 |
oracle | thesaurus_management_system | 5.3.1 |
oracle | timesten_in-memory_database | 𝑥 < 21.1.1.1.0 |
oracle | timesten_in-memory_database | 21.1.1.1.0 |
oracle | utilities_framework | 4.3.0.1.0 ≤ 𝑥 ≤ 4.3.0.6.0 |
oracle | utilities_framework | 4.2.0.3.0 |
oracle | utilities_framework | 4.4.0.0.0 |
oracle | utilities_framework | 4.4.0.2.0 |
oracle | utilities_framework | 4.4.0.3.0 |
oracle | utilities_testing_accelerator | 6.0.0.1.1 |
oracle | utilities_testing_accelerator | 6.0.0.2.2 |
oracle | utilities_testing_accelerator | 6.0.0.3.1 |
oracle | weblogic_server | 12.2.1.3.0 |
oracle | weblogic_server | 12.2.1.4.0 |
oracle | weblogic_server | 14.1.1.0.0 |
oracle | zfs_storage_application_integration_engineering_software | 1.3.3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References