First published: Wed Jan 20 2021(Updated: )
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Services). Supported versions that are affected are 10.3.6.0.0 and 12.1.3.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle WebLogic Server. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Oracle WebLogic Server accessible data. CVSS 3.1 Base Score 2.4 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Agile Engineering Data Management | =6.2.1.0 | |
Oracle Hyperion Infrastructure Technology | =11.1.2.4 | |
Oracle Siebel Ui Framework | <=20.12 | |
Oracle WebLogic Server | =10.3.6.0.0 | |
Oracle WebLogic Server | =12.1.3.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-1996 is a vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware, specifically in the Web Services component.
CVE-2021-1996 affects versions 10.3.6.0.0 and 12.1.3.0.0 of the Oracle WebLogic Server.
An attacker with network access via HTTP can exploit CVE-2021-1996 to compromise the Oracle WebLogic Server.
CVE-2021-1996 has a severity rating of 2.4, which is considered low.
You can find more information about CVE-2021-1996 on the Oracle Security Alerts page.