Unauthenticated Remote Code Execution in Oracle Storage Cloud Software Appliance
CVE-2021-2256
10CRITICAL
What is CVE-2021-2256?
An unauthenticated remote code execution vulnerability exists in the Management Console of Oracle Storage Cloud Software Appliance prior to version 16.3.1.4.2. This flaw allows an attacker with network access over HTTP to compromise the appliance. Exploiting this vulnerability can lead to significant impacts on confidentiality, integrity, and availability, enabling attackers to potentially take control of the appliance and affect additional interconnected products. For protection, it is essential to update the appliance to version 16.3.1.4.2 or later. For more information, refer to Oracle's security alerts.
Affected Version(s)
Cloud Infrastructure < 16.3.1.4.2