CVE-2021-2116 is a vulnerability in the Oracle Application Express Opportunity Tracker component of Oracle Database Server, affecting versions prior to 20.2. This medium-severity vulnerability (CVSS 5.4) allows a low-privileged attacker with a valid user account and network access via HTTP to achieve unauthorized read and limited write access to data within the Opportunity Tracker, requiring user interaction. While no public exploits or active exploitation have been observed, and community discussion is minimal, successful attacks could impact additional products beyond the immediate component.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 20.2CPE matchmatch criteria | cpe:2.3:a:oracle:application_express_opportunity_tracker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.