VDB

CVE-2021-35557

CVE-2021-35557 PUBLISHED CVSS 4.300000190734863 MEDIUM

Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2, 12.2.0.1, 19c and 21c. Easily exploitable vulnerability allows low privileged attacker having Create Table privilege with network access via Oracle Net to compromise Core RDBMS. Successful attacks of this vulnerability can result in unauthorized ability to cause a partial denial of service (partial DOS) of Core RDBMS. CVSS 3.1 Base Score 4.3 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L).

EPSS 0.31% · 54.9th percentile

Risk Scores

CVSS 3.1
4.300000190734863
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
EPSS Score
0.31%
54.9th percentile

Affected Products

VendorProductVersions
oracledatabase12.1.0.2, 12.2.0.1, 19c
Oracle CorporationDatabase - Enterprise Edition12.2.0.1, 19c, 21c

Timeline

  • Oct 20, 2021 CVE Published
  • Oct 21, 2021 EPSS Score
  • Dec 16, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Apr 1, 2022 EPSS Score
  • Apr 8, 2022 EPSS Score
  • Jun 3, 2022 EPSS Score
  • Jul 30, 2022 EPSS Score
  • Sep 24, 2022 EPSS Score
  • Nov 20, 2022 EPSS Score
  • Jan 15, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›