CVE-2021-2351 is a difficult-to-exploit vulnerability in the Advanced Networking Option component of Oracle Database Server versions 12.1.0.2, 12.2.0.1, and 19c. An unauthenticated attacker with network access via Oracle Net can compromise the Advanced Networking Option, requiring human interaction for successful exploitation. This vulnerability carries a high CVSS 3.1 score of 8.3, indicating significant impacts on confidentiality, integrity, and availability, potentially leading to a full takeover of the Advanced Networking Option and affecting additional products. While there is no known active exploitation or public exploit code, the vulnerability has garnered community discussion, including a proof-of-concept video demonstrating its potential. Oracle addressed this issue in the July 2021 Critical Patch Update with changes to Native Network Encryption.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
12.1.0.2CPE matchmatch criteria | cpe:2.3:a:oracle:advanced_networking_option:12.1.0.2:*:*:*:*:*:*:* | ||
12.2.0.1CPE matchmatch criteria | cpe:2.3:a:oracle:advanced_networking_option:12.2.0.1:*:*:*:*:*:*:* | ||
19cCPE matchmatch criteria | cpe:2.3:a:oracle:advanced_networking_option:19c:*:*:*:*:*:*:* | ||
6.2.1.0CPE matchmatch criteria | cpe:2.3:a:oracle:agile_engineering_data_management:6.2.1.0:*:*:*:*:*:*:* | ||
9.3.6CPE matchmatch criteria | cpe:2.3:a:oracle:agile_plm:9.3.6:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.4 Bluesky, 0.2 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.6 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.