CVE-2021-2257 is a vulnerability in the Oracle Storage Cloud Software Appliance, specifically within its Management Console component, affecting versions prior to 16.3.1.4.2. This easily exploitable flaw allows a high-privileged attacker with network access via HTTP to gain unauthorized read access to a subset of the appliance's data. The vulnerability has a CVSS 3.1 Base Score of 4.1 (Medium), indicating a low confidentiality impact. It requires high privileges (PR:H) and network access (AV:N) but has low attack complexity (AC:L). While the vulnerability is in the Storage Cloud Software Appliance, successful attacks could significantly impact additional products. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage regarding this CVE. Oracle recommends updating to version 16.3.1.4.2 or later to mitigate this risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 16.3.1.4.2CPE matchmatch criteria | cpe:2.3:a:oracle:storage_cloud_software_appliance:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.