Unauthenticated Remote Code Execution in Oracle Storage Cloud Software Appliance
CVE-2021-2256
10CRITICAL
Summary
An unauthenticated remote code execution vulnerability exists in the Management Console of Oracle Storage Cloud Software Appliance prior to version 16.3.1.4.2. This flaw allows an attacker with network access over HTTP to compromise the appliance. Exploiting this vulnerability can lead to significant impacts on confidentiality, integrity, and availability, enabling attackers to potentially take control of the appliance and affect additional interconnected products. For protection, it is essential to update the appliance to version 16.3.1.4.2 or later. For more information, refer to Oracle's security alerts.
Affected Version(s)
Cloud Infrastructure < 16.3.1.4.2
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved