CVE-2021-2461
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Vulnerability in the Oracle Communications Interactive Session Recorder product of Oracle Communications (component: Provision API). The supported version that is affected is 6.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Communications Interactive Session Recorder. While the vulnerability is in Oracle Communications Interactive Session Recorder, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Communications Interactive Session Recorder accessible data as well as unauthorized read access to a subset of Oracle Communications Interactive Session Recorder accessible data and unauthorized ability to cause a partial denial of service (partial DOS) of Oracle Communications Interactive Session Recorder. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L).
Una vulnerabilidad en el producto Oracle Communications Interactive Session Recorder de Oracle Communications (componente: Provision API). La versión compatible que está afectada es 6.4. Una vulnerabilidad explotable fácilmente permite a un atacante no autenticado con acceso a la red por medio de HTTP comprometer a Oracle Communications Interactive Session Recorder. Mientras que la vulnerabilidad está en Oracle Communications Interactive Session Recorder, los ataques pueden afectar significativamente a productos adicionales. Los ataques con éxito de esta vulnerabilidad pueden resultar en una actualización, inserción o eliminación no autorizada de algunos de los datos accesibles de Oracle Communications Interactive Session Recorder, así como al acceso de lectura no autorizado a un subconjunto de datos accesibles de Oracle Communications Interactive Session Recorder y a la habilidad no autorizada de causar una denegación parcial de servicio (DOS parcial) de Oracle Communications Interactive Session Recorder. CVSS 3.1 Puntuación Base 8.3 (impactos en la Confidencialidad, Integridad y Disponibilidad). Vector CVSS: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L)
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2020-12-09 CVE Reserved
- 2021-10-20 CVE Published
- 2024-07-05 EPSS Updated
- 2024-09-25 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.oracle.com/security-alerts/cpuoct2021.html | 2021-10-26 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Oracle Search vendor "Oracle" | Communications Interactive Session Recorder Search vendor "Oracle" for product "Communications Interactive Session Recorder" | 6.4 Search vendor "Oracle" for product "Communications Interactive Session Recorder" and version "6.4" | - |
Affected
|