Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).

Project Subscriptions

Vendors Products
Advanced Networking Option Subscribe
Agile Engineering Data Management Subscribe
Agile Plm Subscribe
Agile Product Lifecycle Management For Process Subscribe
Airlines Data Model Subscribe
Application Performance Management Subscribe
Application Testing Suite Subscribe
Argus Analytics Subscribe
Argus Insight Subscribe
Argus Mart Subscribe
Argus Safety Subscribe
Banking Apis Subscribe
Banking Digital Experience Subscribe
Banking Enterprise Default Management Subscribe
Banking Platform Subscribe
Big Data Spatial And Graph Subscribe
Blockchain Platform Subscribe
Clinical Subscribe
Commerce Platform Subscribe
Communications Application Session Controller Subscribe
Communications Billing And Revenue Management Subscribe
Communications Calendar Server Subscribe
Communications Contacts Server Subscribe
Communications Convergent Charging Controller Subscribe
Communications Data Model Subscribe
Communications Design Studio Subscribe
Communications Diameter Intelligence Hub Subscribe
Communications Ip Service Activator Subscribe
Communications Metasolv Solution Subscribe
Communications Network Charging And Control Subscribe
Communications Network Integrity Subscribe
Communications Pricing Design Center Subscribe
Communications Services Gatekeeper Subscribe
Communications Session Report Manager Subscribe
Communications Session Route Manager Subscribe
Data Integrator Subscribe
Demantra Demand Management Subscribe
Documaker Subscribe
Enterprise Data Quality Subscribe
Enterprise Manager Base Platform Subscribe
Enterprise Manager Ops Center Subscribe
Financial Services Analytical Applications Infrastructure Subscribe
Financial Services Behavior Detection Platform Subscribe
Financial Services Enterprise Case Management Subscribe
Financial Services Foreign Account Tax Compliance Act Management Subscribe
Financial Services Model Management And Governance Subscribe
Financial Services Trade-based Anti Money Laundering Subscribe
Flexcube Investor Servicing Subscribe
Flexcube Private Banking Subscribe
Fusion Middleware Subscribe
Goldengate Subscribe
Goldengate Application Adapters Subscribe
Graph Server And Client Subscribe
Health Sciences Clinical Development Analytics Subscribe
Health Sciences Inform Crf Submit Subscribe
Health Sciences Information Manager Subscribe
Healthcare Data Repository Subscribe
Healthcare Foundation Subscribe
Healthcare Translational Research Subscribe
Hospitality Inventory Management Subscribe
Hospitality Opera 5 Subscribe
Hospitality Reporting And Analytics Subscribe
Hospitality Suite8 Subscribe
Hyperion Infrastructure Technology Subscribe
Ilearning Subscribe
Instantis Enterprisetrack Subscribe
Insurance Data Gateway Subscribe
Insurance Insbridge Rating And Underwriting Subscribe
Insurance Policy Administration Subscribe
Insurance Rules Palette Subscribe
Jd Edwards Enterpriseone Tools Subscribe
Oss Support Tools Subscribe
Peoplesoft Enterprise Peopletools Subscribe
Policy Automation Subscribe
Primavera Analytics Subscribe
Primavera Data Warehouse Subscribe
Primavera Gateway Subscribe
Primavera P6 Enterprise Project Portfolio Management Subscribe
Primavera P6 Professional Project Management Subscribe
Primavera Unifier Subscribe
Product Lifecycle Analytics Subscribe
Rapid Planning Subscribe
Real User Experience Insight Subscribe
Retail Analytics Subscribe
Retail Assortment Planning Subscribe
Retail Back Office Subscribe
Retail Central Office Subscribe
Retail Customer Insights Subscribe
Retail Extract Transform And Load Subscribe
Retail Financial Integration Subscribe
Retail Integration Bus Subscribe
Retail Merchandising System Subscribe
Retail Order Broker Subscribe
Retail Order Management System Subscribe
Retail Point-of-service Subscribe
Retail Predictive Application Server Subscribe
Retail Price Management Subscribe
Retail Returns Management Subscribe
Retail Service Backbone Subscribe
Retail Store Inventory Management Subscribe
Retail Xstore Point Of Service Subscribe
Siebel Ui Framework Subscribe
Spatial Studio Subscribe
Storagetek Acsls Subscribe
Storagetek Tape Analytics Subscribe
Thesaurus Management System Subscribe
Timesten In-memory Database Subscribe
Utilities Framework Subscribe
Utilities Testing Accelerator Subscribe
Weblogic Server Subscribe
Zfs Storage Application Integration Engineering Software Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-16810 Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: The July 2021 Critical Patch Update introduces a number of Native Network Encryption changes to deal with vulnerability CVE-2021-2351 and prevent the use of weaker ciphers. Customers should review: "Changes in Native Network Encryption with the July 2021 Critical Patch Update" (Doc ID 2791571.1). CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2024-08-03T16:38:57.682Z

Reserved: 2020-12-09T00:00:00

Link: CVE-2021-2351

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-07-21T15:15:21.827

Modified: 2024-11-21T06:02:56.483

Link: CVE-2021-2351

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses