Vulnerability Name: | CVE-2021-2175 (CCN-200302) | ||||||||||||
Assigned: | 2020-12-09 | ||||||||||||
Published: | 2021-04-20 | ||||||||||||
Updated: | 2023-02-27 | ||||||||||||
Summary: | An unspecified vulnerability in Oracle Database Server related to the Database Vault component could allow an authenticated attacker to obtain sensitive information resulting in a low confidentiality impact using unknown attack vectors. | ||||||||||||
CVSS v3 Severity: | 2.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N) 2.4 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
2.4 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2021-2175 Source: secalert_us@oracle.com Type: Exploit, Third Party Advisory, VDB Entry secalert_us@oracle.com Source: secalert_us@oracle.com Type: Exploit, Third Party Advisory secalert_us@oracle.com Source: XF Type: UNKNOWN oracle-cpuapr2021-cve20212175(200302) Source: CCN Type: IBM Security Bulletin 6474467 (Emptoris Supplier Lifecycle Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Supplier Lifecycle Management Source: CCN Type: IBM Security Bulletin 6474471 (Emptoris Contract Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Contract Management Source: CCN Type: IBM Security Bulletin 6474475 (Emptoris Strategic Supply Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Strategic Supply Management Platform Source: CCN Type: IBM Security Bulletin 6474477 (Emptoris Program Management) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Program Management Source: CCN Type: IBM Security Bulletin 6474479 (Emptoris Sourcing) Multiple Oracle Database Server Vulnerabilities Affect IBM Emptoris Sourcing Source: CCN Type: Oracle Critical Patch Update Advisory - April 2021 Oracle Critical Patch Update Advisory - April 2021 Source: secalert_us@oracle.com Type: Patch, Vendor Advisory secalert_us@oracle.com | ||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |