CVE-2021-21783
 
Severity Score
9.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
1
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
A code execution vulnerability exists in the WS-Addressing plugin functionality of Genivia gSOAP 2.8.107. A specially crafted SOAP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability.
Se presenta una vulnerabilidad de ejecución de código en la funcionalidad del plugin WS-Addressing de Genivia gSOAP versión 2.8.107. Una petición SOAP especialmente diseñada puede conllevar a una ejecución de código remota. Un atacante puede enviar una petición HTTP para desencadenar esta vulnerabilidad
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2021-01-04 CVE Reserved
- 2021-03-25 CVE Published
- 2024-07-28 EPSS Updated
- 2024-08-03 CVE Updated
- 2024-08-03 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-190: Integer Overflow or Wraparound
- CWE-680: Integer Overflow to Buffer Overflow
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2021-1245 | 2024-08-03 |
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpujan2022.html | 2022-07-21 | |
https://www.oracle.com/security-alerts/cpuoct2021.html | 2022-07-21 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Genivia Search vendor "Genivia" | Gsoap Search vendor "Genivia" for product "Gsoap" | 2.8.107 Search vendor "Genivia" for product "Gsoap" and version "2.8.107" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Diameter Signaling Router Search vendor "Oracle" for product "Communications Diameter Signaling Router" | >= 8.0.0 <= 8.5.0 Search vendor "Oracle" for product "Communications Diameter Signaling Router" and version " >= 8.0.0 <= 8.5.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Eagle Application Processor Search vendor "Oracle" for product "Communications Eagle Application Processor" | >= 16.1.0 <= 16.4.0 Search vendor "Oracle" for product "Communications Eagle Application Processor" and version " >= 16.1.0 <= 16.4.0" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Eagle Lnp Application Processor Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" | 46.7 Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "46.7" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Eagle Lnp Application Processor Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" | 46.8 Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "46.8" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Eagle Lnp Application Processor Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" | 46.9 Search vendor "Oracle" for product "Communications Eagle Lnp Application Processor" and version "46.9" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Lsms Search vendor "Oracle" for product "Communications Lsms" | 13.1 Search vendor "Oracle" for product "Communications Lsms" and version "13.1" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Lsms Search vendor "Oracle" for product "Communications Lsms" | 13.2 Search vendor "Oracle" for product "Communications Lsms" and version "13.2" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Lsms Search vendor "Oracle" for product "Communications Lsms" | 13.3 Search vendor "Oracle" for product "Communications Lsms" and version "13.3" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Communications Lsms Search vendor "Oracle" for product "Communications Lsms" | 13.4 Search vendor "Oracle" for product "Communications Lsms" and version "13.4" | - |
Affected
| ||||||
Oracle Search vendor "Oracle" | Tekelec Virtual Operating Environment Search vendor "Oracle" for product "Tekelec Virtual Operating Environment" | >= 3.4.0 <= 3.7.1 Search vendor "Oracle" for product "Tekelec Virtual Operating Environment" and version " >= 3.4.0 <= 3.7.1" | - |
Affected
|