Unauthenticated Remote Code Execution in Oracle Storage Cloud Software Appliance
CVE-2021-2256

10CRITICAL

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

An unauthenticated remote code execution vulnerability exists in the Management Console of Oracle Storage Cloud Software Appliance prior to version 16.3.1.4.2. This flaw allows an attacker with network access over HTTP to compromise the appliance. Exploiting this vulnerability can lead to significant impacts on confidentiality, integrity, and availability, enabling attackers to potentially take control of the appliance and affect additional interconnected products. For protection, it is essential to update the appliance to version 16.3.1.4.2 or later. For more information, refer to Oracle's security alerts.

Affected Version(s)

Cloud Infrastructure < 16.3.1.4.2

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.