CVE-2021-2018 is a high-severity vulnerability (CVSS 8.3) affecting the Advanced Networking Option component of Oracle Database Server 18c and 19c, specifically on Windows platforms. An unauthenticated attacker can exploit this via Oracle Net, but successful attacks require human interaction and have high attack complexity. While targeting the Advanced Networking Option, a successful exploit can lead to its complete takeover and significantly impact additional products, resulting in high confidentiality, integrity, and availability impacts. There is currently no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
18cCPE matchmatch criteria | cpe:2.3:a:oracle:advanced_networking_option:18c:*:*:*:*:*:*:. | ||
19cCPE matchmatch criteria | cpe:2.3:a:oracle:advanced_networking_option:19c:*:*:*:*:*:*:. | ||
11.1.2.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:adaptive_access_manager:11.1.2.3.0:*:*:*:*:*:*:* | ||
11.1.1.9.0CPE matchmatch criteria | cpe:2.3:a:oracle:data_integrator:11.1.1.9.0:*:*:*:*:*:*:* | ||
12.2.1.3.0CPE matchmatch criteria | cpe:2.3:a:oracle:data_integrator:12.2.1.3.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.