Unauthenticated Access Vulnerability in Oracle Communications Interactive Session Recorder
CVE-2021-2461
8.3HIGH
Key Information:
- Vendor
- Oracle
- Vendor
- CVE Published:
- 20 October 2021
Summary
An unauthenticated access vulnerability in Oracle Communications Interactive Session Recorder allows an attacker with network access via HTTP to exploit the system. This flaw can lead to unauthorized modifications (update, insert, delete) of the data accessible by the product, as well as the ability to read a portion of this data without proper authorization. Moreover, the attacker can potentially cause a partial denial of service, disrupting the functionality of Oracle Communications Interactive Session Recorder. This vulnerability could have broader implications, affecting other related products within Oracle's ecosystem.
Affected Version(s)
Communications Interactive Session Recorder 6.4
References
CVSS V3.1
Score:
8.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved