First published: Wed Jul 21 2021(Updated: )
Vulnerability in the Database Vault component of Oracle Database Server. Supported versions that are affected are 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having DBA privilege with network access via Oracle Net to compromise Database Vault. Successful attacks of this vulnerability can result in unauthorized read access to a subset of Database Vault accessible data. CVSS 3.1 Base Score 2.7 (Confidentiality impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:N/A:N).
Credit: secalert_us@oracle.com
Affected Software | Affected Version | How to fix |
---|---|---|
Oracle Database Vault | =12.2.0.1 | |
Oracle Database Vault | =19c |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-2326 is a vulnerability in the Database Vault component of Oracle Database Server.
CVE-2021-2326 affects the 12.2.0.1 and 19c versions of Oracle Database Server.
An attacker with high privileged access (DBA privilege) and network access via Oracle Net can compromise Database Vault using CVE-2021-2326.
CVE-2021-2326 has a severity rating of medium (2.7).
You can find more information about CVE-2021-2326 on the Oracle Security Alerts website: https://www.oracle.com/security-alerts/cpujul2021.html