Vulnerability in Oracle Cloud Infrastructure Storage Gateway Management Console
CVE-2021-2317
10CRITICAL
Summary
A vulnerability exists in the management console of Oracle Cloud Infrastructure Storage Gateway that allows unauthenticated attackers with network access via HTTP to compromise the system. This issue impacts versions prior to 1.4 and may lead to full takeover of the affected product. Successful exploitation can significantly affect the confidentiality, integrity, and availability of the service. Users are advised to update their systems to version 1.4 or higher to mitigate this risk.
Affected Version(s)
Cloud Infrastructure < 1.4
References
CVSS V3.1
Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved