CVE-2021-2018
Published on: 01/20/2021 12:00:00 AM UTC
Last Modified on: 03/23/2021 11:29:07 PM UTC
Certain versions of Windows from Microsoft contain the following vulnerability:
Vulnerability in the Advanced Networking Option component of Oracle Database Server. Supported versions that are affected are 18c and 19c. Difficult to exploit vulnerability allows unauthenticated attacker with network access via Oracle Net to compromise Advanced Networking Option. Successful attacks require human interaction from a person other than the attacker and while the vulnerability is in Advanced Networking Option, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Advanced Networking Option. Note: CVE-2021-2018 affects Windows platform only. CVSS 3.1 Base Score 8.3 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H).
- CVE-2021-2018 has been assigned by
[email protected] to track the vulnerability - currently rated as HIGH severity.
- Affected Vendor/Software:
Oracle Corporation - Advanced Networking Option version = 18c
- Affected Vendor/Software:
Oracle Corporation - Advanced Networking Option version = 19c
CVSS3 Score: 8.3 - HIGH
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | HIGH | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
CHANGED | HIGH | HIGH | HIGH |
CVSS2 Score: 5.1 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | HIGH | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | PARTIAL | PARTIAL |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Oracle Critical Patch Update Advisory - January 2021 | Vendor Advisory www.oracle.com text/html |
![]() |
Related QID Numbers
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Operating System | Microsoft | Windows | - | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
Operating System | Microsoft | Windows | - | All | All | All |
Application | Oracle | Adaptive Access Manager | 11.1.2.3.0 | All | All | All |
Application | Oracle | Adaptive Access Manager | 11.1.2.3.0 | All | All | All |
Application | Oracle | Advanced Networking Option | 18c | All | All | All |
Application | Oracle | Advanced Networking Option | 19c | All | All | All |
Application | Oracle | Advanced Networking Option | 18c | All | All | All |
Application | Oracle | Advanced Networking Option | 19c | All | All | All |
Application | Oracle | Data Integrator | 11.1.1.9.0 | All | All | All |
Application | Oracle | Data Integrator | 12.2.1.3.0 | All | All | All |
Application | Oracle | Data Integrator | 12.2.1.4.0 | All | All | All |
Application | Oracle | Data Integrator | 11.1.1.9.0 | All | All | All |
Application | Oracle | Data Integrator | 12.2.1.3.0 | All | All | All |
Application | Oracle | Data Integrator | 12.2.1.4.0 | All | All | All |
Application | Oracle | Enterprise Manager For Fusion Applications | 13.3.0.0 | All | All | All |
Application | Oracle | Enterprise Manager For Fusion Applications | 13.3.0.0 | All | All | All |
Application | Oracle | Hospitality Simphony | 18.2.7.2 | All | All | All |
Application | Oracle | Hospitality Simphony | 19.1.3 | All | All | All |
Application | Oracle | Hospitality Simphony | 18.2.7.2 | All | All | All |
Application | Oracle | Hospitality Simphony | 19.1.3 | All | All | All |
Application | Oracle | Weblogic Server | 12.2.1.3.0 | All | All | All |
Application | Oracle | Weblogic Server | 12.2.1.3.0 | All | All | All |
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
- cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:adaptive_access_manager:11.1.2.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:adaptive_access_manager:11.1.2.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:advanced_networking_option:18c:*:*:*:*:*:*:.:
- cpe:2.3:a:oracle:advanced_networking_option:19c:*:*:*:*:*:*:.:
- cpe:2.3:a:oracle:advanced_networking_option:18c:*:*:*:*:*:*:.:
- cpe:2.3:a:oracle:advanced_networking_option:19c:*:*:*:*:*:*:.:
- cpe:2.3:a:oracle:data_integrator:11.1.1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:11.1.1.9.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:data_integrator:12.2.1.4.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:enterprise_manager_for_fusion_applications:13.3.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:enterprise_manager_for_fusion_applications:13.3.0.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:hospitality_simphony:18.2.7.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:hospitality_simphony:19.1.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:hospitality_simphony:18.2.7.2:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:hospitality_simphony:19.1.3:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*:
- cpe:2.3:a:oracle:weblogic_server:12.2.1.3.0:*:*:*:*:*:*:*: