Vulnerability in the Unified Audit component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having SYS Account privilege with network access via Oracle Net to compromise Unified Audit. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Unified Audit accessible data. CVSS 3.1 Base Score 2.4 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N).
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://www.oracle.com/security-alerts/cpujan2021.html |
|
History
Thu, 26 Sep 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: oracle
Published: 2021-01-20T14:50:00
Updated: 2024-09-26T18:45:10.307Z
Reserved: 2020-12-09T00:00:00
Link: CVE-2021-2000
Updated: 2024-08-03T16:32:00.946Z
Status : Modified
Published: 2021-01-20T15:15:45.190
Modified: 2024-11-21T06:02:08.910
Link: CVE-2021-2000
No data.