Vulnerability Name: | CVE-2021-2173 (CCN-200300) | ||||||||||||
Assigned: | 2020-12-09 | ||||||||||||
Published: | 2021-04-20 | ||||||||||||
Updated: | 2023-03-15 | ||||||||||||
Summary: | An unspecified vulnerability in Oracle Database Server related to the Recovery component could allow an authenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors. | ||||||||||||
CVSS v3 Severity: | 4.1 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N) 3.6 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C)
3.6 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-2173 Source: secalert_us@oracle.com Type: UNKNOWN secalert_us@oracle.com Source: XF Type: UNKNOWN oracle-cpuapr2021-cve20212173(200300) Source: secalert_us@oracle.com Type: Exploit, Third Party Advisory secalert_us@oracle.com Source: CCN Type: IBM Security Bulletin 6474467 (Emptoris Supplier Lifecycle Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Supplier Lifecycle Management Source: CCN Type: IBM Security Bulletin 6474471 (Emptoris Contract Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Contract Management Source: CCN Type: IBM Security Bulletin 6474475 (Emptoris Strategic Supply Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Strategic Supply Management Platform Source: CCN Type: IBM Security Bulletin 6474477 (Emptoris Program Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Program Management Source: CCN Type: IBM Security Bulletin 6474479 (Emptoris Sourcing) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Sourcing Source: CCN Type: Oracle Critical Patch Update Advisory - April 2021 Oracle Critical Patch Update Advisory - April 2021 Source: secalert_us@oracle.com Type: Patch, Vendor Advisory secalert_us@oracle.com | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |