CVE-2021-2080 is an easily exploitable vulnerability affecting Oracle Configurator versions 12.1 and 12.2, specifically within the UI Servlet component. An unauthenticated attacker can leverage this vulnerability via HTTP, requiring human interaction from a non-attacker to succeed. Successful exploitation can lead to unauthorized access to critical data, complete access to all Oracle Configurator accessible data, and unauthorized modification of some data, with potential significant impact on additional products. The vulnerability carries a CVSS 3.1 Base Score of 8.2 (High), indicating a high severity due to its network attack vector, low attack complexity, and high confidentiality and low integrity impacts. While the vulnerability is easily exploitable, it requires user interaction. Currently, there is no evidence of active exploitation, and no public exploit code is available for Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1CPE matchmatch criteria | cpe:2.3:a:oracle:configurator:12.1:*:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:a:oracle:configurator:12.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.