CVE-2022-21536: High severity oracle enterprise manager vulnerability
Vulnerability in the Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Policy Framework). Supported versions that are affected are 13.4.0.0 and 13.5.0.0. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTTP to compromise Enterprise Manager Base Platform. Successful attacks of this vulnerability can result in takeover of Enterprise Manager Base Platform. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2022-21536?
The severity of CVE-2022-21536 is high.
What is the affected software of CVE-2022-21536?
The affected software of CVE-2022-21536 is Oracle Enterprise Manager Base Platform versions 13.4.0.0 and 13.5.0.0.
How can an attacker exploit CVE-2022-21536?
An unauthenticated attacker with network access via HTTP can exploit CVE-2022-21536.
What is the recommended action to fix CVE-2022-21536?
Install the recommended security patches provided by Oracle to fix CVE-2022-21536.
Where can I find more information about CVE-2022-21536?
You can find more information about CVE-2022-21536 on the Oracle Security Alerts page: https://www.oracle.com/security-alerts/cpujul2022.html.