V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
BDU:2021-06299
BDU
HighConfirmedExploit available

Уязвимость компонента Advanced Networking Option системы управления базами данных Oracle Database Server связана с недостатками процедуры а…

CVSS
8.3
High
EPSS
0.00
p0
Published
2021-01-01
Updated
2021-01-01
Description

Уязвимость компонента Advanced Networking Option системы управления базами данных Oracle Database Server связана с недостатками процедуры аутентификации. Эксплуатация уязвимости может позволить нарушителю, действующему удаленно, реализовать атаку типа «человек посередине» и получить полный контроль над системой

Tags · CWE
Pre-auth
Affected products
Ibm corp. Ibm emptoris contract managementIbm corp. Ibm emptoris contract managementIbm corp. Ibm emptoris contract managementIbm corp. Ibm emptoris strategic supply management platformIbm corp. Ibm emptoris strategic supply management platformIbm corp. Ibm emptoris strategic supply management platformOracle corp. Communications application session controllerOracle corp. Communications metasolv solutionOracle corp. Database serverOracle corp. Database serverOracle corp. Database serverOracle corp. Instantis enterprisetrackOracle corp. Instantis enterprisetrackOracle corp. Instantis enterprisetrackOracle corp. Oracle communications session report managerOracle corp. Oracle communications session route managerOracle corp. Oracle real user experience insightOracle corp. Oracle real user experience insightOracle corp. Primavera gatewayOracle corp. Primavera gateway
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
Timeline
2021-01-01
Published
2021-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: R
Required (R)
Scope
S: C
Changed (C)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.000 · p0
Known exploited (KEV)
No
Known exploits — Сканер-ВС
BDU:2021-06299
bdu_exploit · https://bdu.fstec.ru/vul
Enterprise
Affected software
ProductVendorStatus
ibm emptoris contract managementibm corp.Tracked
ibm emptoris contract managementibm corp.Tracked
ibm emptoris contract managementibm corp.Tracked
ibm emptoris strategic supply management platformibm corp.Tracked
ibm emptoris strategic supply management platformibm corp.Tracked
ibm emptoris strategic supply management platformibm corp.Tracked
communications application session controlleroracle corp.Tracked
communications metasolv solutionoracle corp.Tracked
database serveroracle corp.Tracked
database serveroracle corp.Tracked
database serveroracle corp.Tracked
instantis enterprisetrackoracle corp.Tracked
instantis enterprisetrackoracle corp.Tracked
instantis enterprisetrackoracle corp.Tracked
oracle communications session report manageroracle corp.Tracked
oracle communications session route manageroracle corp.Tracked
oracle real user experience insightoracle corp.Tracked
oracle real user experience insightoracle corp.Tracked
primavera gatewayoracle corp.Tracked
primavera gatewayoracle corp.Tracked