CVE-2021-2207: Low severity oracle database vulnerability
Vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 18c and 19c. Easily exploitable vulnerability allows high privileged attacker having RMAN executable privilege with logon to the infrastructure where Oracle Database - Enterprise Edition executes to compromise Oracle Database - Enterprise Edition. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Database - Enterprise Edition accessible data. CVSS 3.1 Base Score 2.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-2207?
CVE-2021-2207 is a vulnerability in the Oracle Database - Enterprise Edition component of Oracle Database Server.
Which versions of Oracle Database Server are affected by CVE-2021-2207?
Versions 12.1.0.2, 12.2.0.1, 18c, and 19c of Oracle Database Server are affected by CVE-2021-2207.
How severe is CVE-2021-2207?
CVE-2021-2207 has a severity rating of 2.3, which is classified as low.
How can CVE-2021-2207 be exploited?
CVE-2021-2207 can be exploited by a high privileged attacker with RMAN executable privilege and logon access to the infrastructure.
Where can I find more information about CVE-2021-2207?
You can find more information about CVE-2021-2207 at the following references: [Packet Storm Security](http://packetstormsecurity.com/files/174448/Oracle-RMAN-Missing-Auditing.html) and [Oracle Security Alerts](https://www.oracle.com/security-alerts/cpuapr2021.html).