2024-12-08 03:06:42 +00:00

112 lines
4.5 KiB
JSON

{
"id": "CVE-2021-2138",
"sourceIdentifier": "secalert_us@oracle.com",
"published": "2021-03-03T06:15:15.017",
"lastModified": "2024-11-21T06:02:27.703",
"vulnStatus": "Modified",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Vulnerability in the Oracle Cloud Infrastructure Data Science Notebook Sessions. Easily exploitable vulnerability allows low privileged attacker with access to the physical communication segment attached to the hardware where the Oracle Cloud Infrastructure Data Science Notebook Sessions executes to compromise Oracle Cloud Infrastructure Data Science Notebook Sessions. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle Cloud Infrastructure Data Science Notebook Sessions accessible data as well as unauthorized read access to a subset of Oracle Cloud Infrastructure Data Science Notebook Sessions accessible data. All affected customers were notified of CVE-2021-2138 by Oracle. CVSS 3.1 Base Score 4.6 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)"
},
{
"lang": "es",
"value": "Vulnerabilidad en Oracle Cloud Infrastructure Data Science Notebook Sessions. La vulnerabilidad f\u00e1cilmente explotable permite a un atacante con pocos privilegios y con acceso al segmento de comunicaci\u00f3n f\u00edsica conectado al hardware donde se ejecuta Oracle Cloud Infrastructure Data Science Notebook Sessions comprometer Oracle Cloud Infrastructure Data Science Notebook Sessions. Los ataques exitosos de esta vulnerabilidad pueden dar lugar a la actualizaci\u00f3n no autorizada, insertar o eliminar algunos de los datos accesibles de Oracle Cloud Infrastructure Data Science Notebook Sessions, as\u00ed como el acceso de lectura no autorizado a un subconjunto de datos accesibles de Oracle Cloud Infrastructure Data Science Notebook Sessions. Todos los clientes afectados fueron notificados de CVE-2021-2138 por Oracle. Puntuaci\u00f3n base de CVSS 3.1: 4,6 (impactos en la confidencialidad y la integridad). Vector CVSS: (CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N)"
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "secalert_us@oracle.com",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N",
"baseScore": 4.6,
"baseSeverity": "MEDIUM",
"attackVector": "ADJACENT_NETWORK",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "LOW",
"integrityImpact": "LOW",
"availabilityImpact": "NONE"
},
"exploitabilityScore": 2.1,
"impactScore": 2.5
}
],
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:A/AC:L/Au:S/C:P/I:P/A:N",
"baseScore": 4.1,
"accessVector": "ADJACENT_NETWORK",
"accessComplexity": "LOW",
"authentication": "SINGLE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 5.1,
"impactScore": 4.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:oracle:cloud_infrastructure_data_science:*:*:*:*:*:*:*:*",
"matchCriteriaId": "EAAE264D-28AD-4C66-82E6-6258FA8EDAC1"
}
]
}
]
}
],
"references": [
{
"url": "https://support.oracle.com",
"source": "secalert_us@oracle.com",
"tags": [
"Permissions Required"
]
},
{
"url": "https://support.oracle.com",
"source": "af854a3a-2127-422b-91ae-364da2661108",
"tags": [
"Permissions Required"
]
}
]
}