Oracle Enterprise Manager Base Platform Policy Framework Vulnerability
CVE-2021-2137
8.8HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 October 2021
Summary
This vulnerability allows an attacker with low privileges and network access via HTTP to exploit the Policy Framework component of Oracle's Enterprise Manager Base Platform. Successful attacks enable the attacker to take control over the platform, resulting in potential unauthorized access and manipulation of sensitive information. The affected versions, 13.4.0.0 and 13.5.0.0, highlight the necessity for prompt updates to mitigate risks associated with this vulnerability.
Affected Version(s)
Enterprise Manager Base Platform 13.4.0.0
Enterprise Manager Base Platform 13.5.0.0
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved