Oracle Storage Cloud Software Appliance Vulnerability Exposes Data
CVE-2021-2257

4.1MEDIUM

Key Information:

Vendor
Oracle
Vendor
CVE Published:
22 April 2021

Summary

A vulnerability exists in the Oracle Storage Cloud Software Appliance that could allow a high-privileged attacker with network access via HTTP to potentially gain unauthorized read access to sensitive data. This issue primarily affects versions prior to 16.3.1.4.2. It is crucial for users to promptly update their systems to the latest version to mitigate risks associated with this vulnerability. For further information and updates, users are encouraged to refer to Oracle’s official documentation.

Affected Version(s)

Cloud Infrastructure < 16.3.1.4.2

References

CVSS V3.1

Score:
4.1
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.