CVE-2021-2328

HIGH

Oracle Text 12.1.0.2, 12.2.0.1, 19c - Authenticated Remote Code Execution via Oracle Net

Title source: llm
STIX 2.1

Description

Vulnerability in the Oracle Text component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1 and 19c. Easily exploitable vulnerability allows high privileged attacker having Create Any Procedure, Alter Any Table privilege with network access via Oracle Net to compromise Oracle Text. Successful attacks of this vulnerability can result in takeover of Oracle Text. CVSS 3.1 Base Score 7.2 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).

References (1)

Core 1
Core References

Scores

CVSS v3 7.2
EPSS 0.0141
EPSS Percentile 80.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

Status published
Products (3)
oracle/text 12.1.0.2
oracle/text 12.2.0.1
oracle/text 19c
Published Jul 21, 2021
Tracked Since Feb 18, 2026