CVE-2021-1996: Low severity oracle agile engineering data management vulnerability
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-1996?
CVE-2021-1996 is a vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware, specifically in the Web Services component.
How does CVE-2021-1996 affect the Oracle WebLogic Server?
CVE-2021-1996 affects versions 10.3.6.0.0 and 12.1.3.0.0 of the Oracle WebLogic Server.
How can an attacker exploit CVE-2021-1996?
An attacker with network access via HTTP can exploit CVE-2021-1996 to compromise the Oracle WebLogic Server.
What is the severity of CVE-2021-1996?
CVE-2021-1996 has a severity rating of 2.4, which is considered low.
Where can I find more information about CVE-2021-1996?
You can find more information about CVE-2021-1996 on the Oracle Security Alerts page.