CVE-2021-2333 is a medium-severity vulnerability affecting Oracle XML DB in Oracle Database Server versions 12.1.0.2, 12.2.0.1, and 19c. An attacker with Alter User privileges and network access via Oracle Net can exploit this to gain unauthorized access to critical or all Oracle XML DB accessible data. With a CVSS score of 4.9, this vulnerability is easily exploitable but requires high privileges, impacting confidentiality. There is currently no public exploit code available, and it shows minimal community discussion or media coverage, indicating it is not actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:xml_database:12.1.0.2:*:*:*:*:*:*:* | ||
12.2.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:xml_database:12.2.0.1:*:*:*:*:*:*:* | ||
19cCPE matchmatch criteria | cpe:2.3:a:oracle:xml_database:19c:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.